Manuals
/
Lucent Technologies
/
Computer Equipment
/
Network Card
Lucent Technologies
Ethereal
manual
Introduction
Models:
Ethereal
1
27
199
199
Download
199 pages
450 b
24
25
26
27
28
29
30
31
Install
FAQ
Reporting Problems
Find Next command
Time adjustment
Preference/recent settings
Resolution
How to
What is
Service Response Time
Page 27
Image 27
Introduction
13
Page 26
Page 28
Page 27
Image 27
Page 26
Page 28
Contents
V2.0.2 16376 for Ethereal
Ethereal Users Guide
Ethereal Users Guide V2.0.2 16376 for Ethereal
Page
Table of Contents
Page
Page
Page
Foreword
Preface
Who should read this document?
Acknowledgements
About this document
Where to get the latest copy of this document?
Providing feedback about this document
Preface Xiv
Some intended purposes
What is Ethereal?
Features
Introduction
Export files for many other capture programs
Many protocol decoders
Open Source Software
What Ethereal is not
Platforms Ethereal runs on
Unix
Linux
Microsoft Windows
Where to get Ethereal?
Rose by any other name
Brief history of Ethereal
Development and maintenance of Ethereal
Mailing Lists
Reporting problems and getting help
FAQ
Website Wiki
Reporting Crashes on UNIX/Linux platforms
Reporting Problems
Reporting Crashes on Windows platforms
Introduction
Introduction
Building and Installing Ethereal
Download all required files
Obtaining the source and binary distributions
Example 2.1. Building GTK+ from source
Before you build Ethereal under Unix
Example 2.2. Building and installing libpcap
Example 2.5. Installing debs under Debian
Unix
Building Ethereal from source under
Page
Installing the binaries under Unix
Installing from rpms under RedHat and alike
Installing from debs under Debian
Troubleshooting during the install on Unix
Building from source under Windows
Install Ethereal
Installing Ethereal under Windows
Install WinPcap
Update Ethereal
Update WinPcap
Uninstall Ethereal
Uninstall WinPcap
Building and Installing Ethereal
User Interface
Start Ethereal
Main window
Main window
User Interface Current program state and the captured data
Menu
Merge
File menu
Menu Item Accelerator Description Open
Open Recent
Files
Menu Item Accelerator Description Save
Save As
File Set List
Ted Packet Bytes
Menu Item Accelerator Description Export
Pdml file
Export Selec
Edit menu
Marking packets for details
User Interface
View Menu View menu items
View menu
Beginning
Fields Time of Day, Date and Time of Day
Seconds Since Beginning of Capture and Seconds Since
Previous Packet are mutually exclusive
Resize All
Menu Item Accelerator Description Zoom
Zoom Out
Normal Size
Go menu
Menu Item Accelerator Description Last Packet
Capture menu
Saving filters
Analyze Menu Analyze menu items
Analyze menu
TCP
Follow
Statistics menu items
Statistics menu
VoIP Calls
225
Message
Types
10. The Help Menu Help menu items
Help menu
Page
11. The Main toolbar Main toolbar items
Main toolbar
Packet Go To Last Pack
Go Back
Go Forward
First
Tion 9.3, Packet colorization
12. The Filter toolbar
Filter toolbar
13. The Packet List pane
Packet List pane
14. The Packet Details pane
Packet Details pane
15. The Packet Bytes pane
Packet Bytes pane
17. The initial Statusbar
Statusbar
User Interface
Capturing Live Network Data
Prerequisites
Capture Options dialog box
Start Capturing
Capture Interfaces dialog box
Packets/s
Prepare
Capture Options dialog box
Capture frame
Interface
Capture packets in promiscuous
IP address
Link-layer header type
Buffer size n megabytes
Stop Capture... frame
Capture Files frame
Name Resolution frame
Display Options frame
Buttons
Capture files and file modes
Capture file mode selected by capture options
Multiple files, ring buffer
Multiple files, continuous
Link-layer header type
Ether srcdst host ehost
Filtering while capturing
Example 4.2. Capturing all telnet traffic not from
Srcdst host host
Tcpudp srcdst port port
Gateway host host
Srcdst net net mask
Masklen len
Stop the running capture
While a Capture is running
Restart a running capture
Using the toolbar item
Capturing Live Network Data
File Input / Output and Printing
Open Capture File dialog box
Open capture files
Input File Formats
Page
Save Capture File As dialog box
Saving captured packets
Tip
Output File Formats
Merge with Capture File dialog box
Merging capture files
Page
List Files dialog box
File Sets
Exporting data
Export as Plain Text File dialog box
Export as PostScript File dialog box
Export as Psml File dialog box
Export as CSV Comma Seperated Values File dialog box
Export as Psml File dialog box
Export as Pdml File dialog box
Export Selected Packet Bytes dialog box
Export selected packet bytes dialog box
Page
Printing packets
Print dialog box
Printer
Lpr -Pmypostscript
10. The Packet Range frame
Packet Range frame
11. The Packet Format frame
Packet Format frame
File Input / Output and Printing
Viewing packets you have captured
Working with captured packets
Function overview of the pop-up menus
Copy
Lis Byt Menu Description Tail
Decode As
New Window Resolve name
Follow TCP Stream
Mark Packet toggle
Filter Field Reference
Protocol Properties
Go to Corresponding Packet
Export Selected Packet Bytes
Filtering on the TCP protocol
Filtering packets while viewing
Page
Display Filter comparison operators
Building display filter expressions
Display filter fields
Comparing values
Display Filter Field Types
Combining expressions
Display Filter Logical Operations
Common mistake
Filter Expression dialog box
Filter Expression dialog box
Range
Cancel
Value
Predefined values
Capture Filters and Display Filters dialog boxes
Defining and saving filters
Filter name
New
Delete
Filter
Hex Value
Finding packets
Find Packet dialog box
Display filter
Find Next command
Find Previous command
Down
Go to a specific packet
Marking packets
Packet time referencing
Time display formats and time references
Page
Working with captured packets 119
Advanced Features
Follow TCP stream dialog box
Following TCP streams
Page
How Ethereal handles it
What is it?
Reassembling is disabled by default
Packet Reassembling
Name Resolution
Ethernet name resolution MAC layer
IP name resolution network layer
TCP/UDP port name resolution transport layer
IPX name resolution network layer
Advanced Features 126
Statistics
Summary window
Summary window
Page
Protocol Hierarchy window
Protocol Hierarchy window
Page
What is an Endpoint?
Endpoints
Endpoints window
Protocol specific Endpoint List windows
Protocol specific Conversation List windows
What is a Conversation?
Conversations
Conversations window
IO Graphs window
Graphs
Axis
Page
Service Response Time
Service Response Time DCE-RPC window
Fibre Channel 225 RAS
DCE-RPC Statistic for ... window
Protocol specific statistics windows
Statistics 140
Customizing Ethereal
Filesize ue
Start Ethereal from the command line
Example 9.1. Help information available from Ethereal
Duration ue
Only
Durationue
Filesizeue
Capture buffer size Win32
Ethereal -o mgcp.displaydissecttreeTRUE
Preference/recent settings
Font
Name resolving flags
Statistics-string
Time stamp format
Savefile
Capture link type
Coloring Rules dialog box
Packet colorization
Choose color dialog box
Using color filters with Ethereal
Control Protocol dissection
Enabled Protocols dialog box
Page
Decode As dialog box
User Specified Decodes
Decode As Show dialog box
Show User Specified Decodes
Preferences dialog box
Preferences
Customizing Ethereal 154
Customizing Ethereal 155
Table A.1. Configuration files and folders overview
Appendix A. Configuration and other Files and Folders
Preferences/ethereal.conf
Windows folders
Configuration files and folders overview. If an address is
Disabledprotos
Windows folders
Windows profiles
Plugins folder
95/98/ME
98/ME with enabled user pro
Windows NT/2000/XP roaming profiles
Windows temporary folder
Configuration and other Files Folders 161
Appendix B. Protocols and Protocol Fields
Appendix C. Related command line tools
Tcpdump Capturing with tcpdump for viewing with Ethereal
Tethereal Terminal-based Ethereal
Example C.1. Help information available from capinfos
Capinfos Print information about capture files
Example C.2. Help information available from editcap
Editcap Edit capture files
Related command line tools
Snaplen
Time adjustment
Encap type
Capture type
Example C.3. Help information available from mergecap
Mergecap Merging multiple capture files into one
171
Example C.4. Simple example of using mergecap
Example C.5. Help information available for text2pcap
Text2pcap Converting Ascii hexdumps to network captures
Hexoct
Filename
Srcport destport
L3pid
Idl2eth Creating dissectors from Corba IDL files
Why do this?
How to use idl2eth
Prerequisites to using idl2eth
Todo
Limitations
Related command line tools 179
GNU General Public License
Appendix D. This Documents License GPL
181
182
183
184
185
Top
Page
Image
Contents