Wireshark is one of the most important tools you can utilize for looking at what is happening on the network. It allows you to look at every piece of information about this packet you could ever want to see. It starts at the physical layer and goes up from there. Wireshark was originally called Ethereal, but later changed to Wireshark.
Wireshark is very similar to tcpdump, but has a graphical interface tied around it and has some additional features, as follows:
- Color coding packet types that can be changed and customized
- Ability to look at new protocols with plugins
- Voice over IP calls can be captured as well
- Ability to click on packets and follow the stream
Here is a screenshot of Wireshark when it first starts up. You can enter ...