What is Ethereal?

Every network manager at some time or other needs a tool that can capture packets off the network and analyze them. In the past, such tools were either very expensive, propietary, or both. However, with the advent of Ethereal, all that has changed.

Ethereal is perhaps one the best open source packet sniffers available today. The following are some of the features Ethereal provides:

However, to really appreciate its power, you have to start using it.

Figure 1 shows Ethereal having captured some packets and waiting for you to examine the packets.

Figure 1. Ethereal captures packets and allows you to examine their content.

In addition, because all the source code for Ethereal is freely available, it is very easy for people to add new protocols to Ethereal, either as modules, or built into the source.

There are currently protocol decoders (or dissectors, as they are known in Ethereal), for a great many protocols, including: