Introduction to Ethereal

The Ethereal package contains a network protocol analyzer, also known as a “sniffer”. This is useful for analyzing data captured “off the wire” from a live network connection, or data read from a capture file. Ethereal provides both a graphical and TTY-mode front-end for examining captured network packets from over 500 protocols, as well as the capability to read capture files from many other popular network analyzers.

Package Information

Additional Downloads

From this page you can download many different docs in a variety of formats.

Ethereal dependencies


GLib-1.2.10 or GLib-2.10.3 (to build the TTY-mode front-end only)



pkg-config-0.20, GTK+-1.2.10 or GTK+-2.8.20 (to build the GUI front-end), OpenSSL-0.9.8d, Heimdal-0.7.2 or MIT Kerberos V5-1.6, Python-2.4.4, PCRE-6.7, GnuTLS (which needs libgpg-error then libgcrypt), Net-SNMP, adns, and Lua

User Notes:

Kernel Configuration

The kernel must have the Packet protocol enabled for Ethereal to capture live packets from the network. Enable the Packet protocol by choosing “Y” in the “Networking” – “Packet socket” configuration parameter. Alternatively, build the af_packet.ko module by choosing “M” in this parameter.

Installation of Ethereal

Install Ethereal by running the following commands:

./configure --prefix=/usr \
            --sysconfdir=/etc \
            --enable-threads &&

This package does not come with a test suite.

Now, as the root user:

make install &&
install -v -m644 FAQ README{,.linux} doc/README.* doc/*.{pod,txt} \
                 /usr/share/ethereal &&
install -v -m644 -D ethereal.desktop \
                    /usr/share/applications/ethereal.desktop &&
install -v -m644 -D image/elogo3d48x48.png \
                    /usr/share/pixmaps/ethereal.png &&
install -v -m755 -d /usr/share/pixmaps/ethereal &&
install -v -m644 image/*.{png,ico,xpm,bmp} \

If you downloaded any of the documentation files from the page listed in the 'Additional Downloads', install them by issuing the following commands as the root user:

install -v -m755 -d /usr/share/doc/ethereal-0.99.0 &&
install -v -m644 <Downloaded_Files> /usr/share/doc/ethereal-0.99.0

Command Explanations

--enable-threads: This parameter enables the use of threads in ethereal.

--with-ssl: This parameter enables the use of the OpenSSL libcrypto library.

Configuring Ethereal

Config Files

/etc/ethereal.conf and ~/.ethereal/preferences

Configuration Information

Though the default configuration parameters are very sane, reference the configuration section of the Ethereal User's Guide for configuration information. Most of Ethereal's configuration can be accomplished using the menu options of the ethereal graphical interface.



If you want to look at packets, make sure you don't filter them out with iptables-1.3.6. If you want to exclude certain classes of packets, it is more efficient to do it with iptables than Ethereal.


Installed Programs: capinfos, dftest, editcap, ethereal, idl2eth, mergecap, randpkt, tethereal and text2pcap
Installed Libraries:, and numerous dissector plugin modules
Installed Directories: /usr/lib/ethereal, /usr/share/ethereal and /usr/share/pixmaps/ethereal

Short Descriptions


reads a saved capture file and returns any or all of several statistics about that file. It is able to detect and read any capture supported by the Ethereal package.


is a display-filter-compiler test program.


edits and/or translates the format of capture files. It knows how to read libpcap capture files, including those of tcpdump, Ethereal and other tools that write captures in that format.


is a GUI network protocol analyzer. It lets you interactively browse packet data from a live network or from a previously saved capture file.


takes a user specified CORBA IDL file and generates “C” source code that can be used to create an Ethereal plugin.


combines multiple saved capture files into a single output file.


creates random-packet capture files.


is a TTY-mode network protocol analyzer. It lets you capture packet data from a live network or read packets from a previously saved capture file.


reads in an ASCII hex dump and writes the data described into a libpcap-style capture file.

contains functions used by the Ethereal programs to perform filtering and packet capturing.

is a library being developed as a future replacement for libpcap, the current standard Unix library for packet capturing. For more information, see the README file in the source wiretap directory.

Last updated on 2007-01-18 13:38:19 -0600