Wireshark 0.99.6

Review : Protocol analysis for the masses

Wireshark 0.99.6 is a free, flexible and feature-packed network protocol analyser

Written by Dave Bailey

Larger Image

Wireshark version 0.99.6 is a free, flexible program for protocol capture and analysis that is available for Windows, Mac OS X, Linux and Unix systems.

We installed the Windows version, and within five minutes we were able to capture network traffic on our Windows XP Professional Dell Precision M50 notebook. For comparison, we also installed the software on Windows 2000 Professional, Windows Server 2003, Vista Enterprise, and Mandriva and Red Hat Linux, and again experienced no problems.

Advertisement

On firing up Wireshark, the user is presented with a menu bar underneath which is a blank grey pane. Choosing a network interface under the “Capture” tab and pressing “Start” sets off the packet capture process. The screen then divides into three panes, with the main one on top displaying a range of useful information, including the frame number of the packet, time, packet source, packet destination and protocol type.

Once packet data has been captured, it was easy to set up a display filter to only show packets of a certain protocol, to check, for example, whether any system on the network was using IPv6. Filters are also useful when connecting to mirror or span ports of routers and switches because they make it easy for users to pull out the specific protocol or protocols that they are looking for. Wireshark also allows users to set up expressions using Boolean-type operators, making it easy to check for packets containing certain MAC addresses.

Captured data can be analysed while still connected to the interface or saved offline for later analysis. Most packet capture formats are supported, including tcpdump (libpcap), Network General (now NetScout) Sniffer, Network Instruments Observer, Visual Networks Visual UpTime, and the WildPackets Peek family.

Clicking on the “Statistics” tab brings a wealth of analysis tools, such as flow graphs, I/O data transfer rate graphed over time and many others. Wireshark also has voice over IP (VoIP) call capture features for troubleshooting IP telephony problems.

Overall, this is an impressive package. The GUI is not as polished as others we have seen, but is still pretty good for a free application.

Tags:

Product overview

  • Price: Free
  • Manufacturer: Wireshark
  • Specifications:

Best prices

Ratings

  • Overall rating: 5
  • Features: n/a
  • Performance rating: n/a
  • Value for money: n/a
  • Average user rating:
Rate this product

Verdict

Wireshark version 0.99.6 offers network managers a versatile network protocol analyser that is easy to set up and use and can dissect almost all protocols The range of features and the wealth of analysis tools make it unbeatable for a free program.

Pros : Free; versions available for most platforms.

Cons : GUI not as polished as paid-for competitor programs.

See also:

Advertisements

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation