Manuals
/
Lucent Technologies
/
Computer Equipment
/
Network Card
Lucent Technologies
Ethereal
manual
Capturing Live Network Data
Models:
Ethereal
1
90
199
199
Download
199 pages
450 b
87
88
89
90
91
92
93
94
Install
FAQ
Reporting Problems
Find Next command
Time adjustment
Preference/recent settings
Resolution
How to
What is
Service Response Time
Page 90
Image 90
Capturing Live Network Data
76
Page 89
Page 91
Page 90
Image 90
Page 89
Page 91
Contents
Ethereal Users Guide
V2.0.2 16376 for Ethereal
Ethereal Users Guide V2.0.2 16376 for Ethereal
Page
Table of Contents
Page
Page
Page
Preface
Foreword
Who should read this document?
Acknowledgements
About this document
Where to get the latest copy of this document?
Providing feedback about this document
Preface Xiv
Introduction
What is Ethereal?
Features
Some intended purposes
Export files for many other capture programs
Many protocol decoders
Open Source Software
What Ethereal is not
Platforms Ethereal runs on
Unix
Linux
Microsoft Windows
Where to get Ethereal?
Rose by any other name
Brief history of Ethereal
Development and maintenance of Ethereal
Website Wiki
Reporting problems and getting help
FAQ
Mailing Lists
Reporting Problems
Reporting Crashes on UNIX/Linux platforms
Reporting Crashes on Windows platforms
Introduction
Building and Installing Ethereal
Introduction
Obtaining the source and binary distributions
Download all required files
Before you build Ethereal under Unix
Example 2.1. Building GTK+ from source
Example 2.2. Building and installing libpcap
Example 2.5. Installing debs under Debian
Building Ethereal from source under
Unix
Page
Installing the binaries under Unix
Installing from rpms under RedHat and alike
Installing from debs under Debian
Troubleshooting during the install on Unix
Building from source under Windows
Installing Ethereal under Windows
Install Ethereal
Install WinPcap
Update Ethereal
Update WinPcap
Uninstall Ethereal
Uninstall WinPcap
Building and Installing Ethereal
User Interface
Start Ethereal
Main window
Main window
User Interface Current program state and the captured data
Menu
Open Recent
File menu
Menu Item Accelerator Description Open
Merge
File Set List
Menu Item Accelerator Description Save
Save As
Files
Export Selec
Menu Item Accelerator Description Export
Pdml file
Ted Packet Bytes
Edit menu
User Interface
Marking packets for details
View menu
View Menu View menu items
Previous Packet are mutually exclusive
Fields Time of Day, Date and Time of Day
Seconds Since Beginning of Capture and Seconds Since
Beginning
Normal Size
Menu Item Accelerator Description Zoom
Zoom Out
Resize All
Go menu
Menu Item Accelerator Description Last Packet
Capture menu
Saving filters
Analyze menu
Analyze Menu Analyze menu items
Follow
TCP
Statistics menu
Statistics menu items
Types
225
Message
VoIP Calls
Help menu
10. The Help Menu Help menu items
Page
Main toolbar
11. The Main toolbar Main toolbar items
First
Go Back
Go Forward
Packet Go To Last Pack
Tion 9.3, Packet colorization
Filter toolbar
12. The Filter toolbar
Packet List pane
13. The Packet List pane
Packet Details pane
14. The Packet Details pane
Packet Bytes pane
15. The Packet Bytes pane
Statusbar
17. The initial Statusbar
User Interface
Capturing Live Network Data
Prerequisites
Start Capturing
Capture Options dialog box
Capture Interfaces dialog box
Packets/s
Prepare
Capture Options dialog box
Capture frame
Interface
Buffer size n megabytes
IP address
Link-layer header type
Capture packets in promiscuous
Capture Files frame
Stop Capture... frame
Name Resolution frame
Display Options frame
Buttons
Capture file mode selected by capture options
Capture files and file modes
Multiple files, continuous
Multiple files, ring buffer
Link-layer header type
Srcdst host host
Filtering while capturing
Example 4.2. Capturing all telnet traffic not from
Ether srcdst host ehost
Masklen len
Gateway host host
Srcdst net net mask
Tcpudp srcdst port port
While a Capture is running
Stop the running capture
Using the toolbar item
Restart a running capture
Capturing Live Network Data
File Input / Output and Printing
Open capture files
Open Capture File dialog box
Input File Formats
Page
Saving captured packets
Save Capture File As dialog box
Tip
Output File Formats
Merging capture files
Merge with Capture File dialog box
Page
File Sets
List Files dialog box
Exporting data
Export as Plain Text File dialog box
Export as PostScript File dialog box
Export as CSV Comma Seperated Values File dialog box
Export as Psml File dialog box
Export as Pdml File dialog box
Export as Psml File dialog box
Export selected packet bytes dialog box
Export Selected Packet Bytes dialog box
Page
Printing packets
Print dialog box
Printer
Lpr -Pmypostscript
Packet Range frame
10. The Packet Range frame
Packet Format frame
11. The Packet Format frame
File Input / Output and Printing
Working with captured packets
Viewing packets you have captured
Function overview of the pop-up menus
New Window Resolve name
Lis Byt Menu Description Tail
Decode As
Copy
Mark Packet toggle
Follow TCP Stream
Filter Field Reference
Protocol Properties
Go to Corresponding Packet
Export Selected Packet Bytes
Filtering packets while viewing
Filtering on the TCP protocol
Page
Comparing values
Building display filter expressions
Display filter fields
Display Filter comparison operators
Combining expressions
Display Filter Field Types
Display Filter Logical Operations
Common mistake
Filter Expression dialog box
Filter Expression dialog box
Predefined values
Cancel
Value
Range
Defining and saving filters
Capture Filters and Display Filters dialog boxes
Filter
New
Delete
Filter name
Display filter
Finding packets
Find Packet dialog box
Hex Value
Find Next command
Find Previous command
Down
Go to a specific packet
Marking packets
Time display formats and time references
Packet time referencing
Page
Working with captured packets 119
Advanced Features
Following TCP streams
Follow TCP stream dialog box
Page
Packet Reassembling
What is it?
Reassembling is disabled by default
How Ethereal handles it
Name Resolution
Ethernet name resolution MAC layer
IP name resolution network layer
IPX name resolution network layer
TCP/UDP port name resolution transport layer
Advanced Features 126
Statistics
Summary window
Summary window
Page
Protocol Hierarchy window
Protocol Hierarchy window
Page
What is an Endpoint?
Endpoints
Endpoints window
Protocol specific Endpoint List windows
Conversations window
What is a Conversation?
Conversations
Protocol specific Conversation List windows
IO Graphs window
Graphs
Axis
Page
Service Response Time
Service Response Time DCE-RPC window
Fibre Channel 225 RAS
DCE-RPC Statistic for ... window
Protocol specific statistics windows
Statistics 140
Customizing Ethereal
Duration ue
Start Ethereal from the command line
Example 9.1. Help information available from Ethereal
Filesize ue
Capture buffer size Win32
Durationue
Filesizeue
Only
Name resolving flags
Preference/recent settings
Font
Ethereal -o mgcp.displaydissecttreeTRUE
Capture link type
Time stamp format
Savefile
Statistics-string
Packet colorization
Coloring Rules dialog box
Choose color dialog box
Using color filters with Ethereal
Enabled Protocols dialog box
Control Protocol dissection
Page
User Specified Decodes
Decode As dialog box
Show User Specified Decodes
Decode As Show dialog box
Preferences
Preferences dialog box
Customizing Ethereal 154
Customizing Ethereal 155
Appendix A. Configuration and other Files and Folders
Table A.1. Configuration files and folders overview
Windows folders
Preferences/ethereal.conf
Disabledprotos
Configuration files and folders overview. If an address is
Windows folders
Windows profiles
Plugins folder
Windows temporary folder
98/ME with enabled user pro
Windows NT/2000/XP roaming profiles
95/98/ME
Configuration and other Files Folders 161
Appendix B. Protocols and Protocol Fields
Appendix C. Related command line tools
Tcpdump Capturing with tcpdump for viewing with Ethereal
Tethereal Terminal-based Ethereal
Capinfos Print information about capture files
Example C.1. Help information available from capinfos
Editcap Edit capture files
Example C.2. Help information available from editcap
Related command line tools
Capture type
Time adjustment
Encap type
Snaplen
Mergecap Merging multiple capture files into one
Example C.3. Help information available from mergecap
171
Example C.4. Simple example of using mergecap
Text2pcap Converting Ascii hexdumps to network captures
Example C.5. Help information available for text2pcap
Filename
Hexoct
L3pid
Srcport destport
Prerequisites to using idl2eth
Why do this?
How to use idl2eth
Idl2eth Creating dissectors from Corba IDL files
Todo
Limitations
Related command line tools 179
Appendix D. This Documents License GPL
GNU General Public License
181
182
183
184
185
Top
Page
Image
Contents