In this section we explore installing Ethereal under Windows from the binary packages.
You may acquire a binary installer of Ethereal at http://www.ethereal.com/download.html#releases.
Simply download the installer and execute it.
![]() | Note! |
---|---|
Since Ethereal Version 0.10.12, the WinPcap installer has become part of the main Ethereal installer, so you don't need to download and install two separate packages any longer. |
Beside the usual installer options like where to install the program, there are several optional components.
![]() | Tip! |
---|---|
If you are unsure which settings to select, just keep the default settings. |
The Components (both Ethereal GTK1 and 2 cannot be installed at the same time):
Etheral GTK1 - Ethereal is a GUI network protocol analyzer.
Etheral GTK2 - Ethereal is a GUI network protocol analyzer (using the modern GTK2 GUI toolkit, recommended).
GTK-Wimp - GTKWimp is the GTK2 windows impersonator (native Win32 look and feel, recommended).
Tethereal - Tethereal is a command-line based network protocol analyzer.
The dissection extensions for Ethereal and Tethereal:
Dissector Plugins - Plugins with some extended dissections.
Tree Statistics Plugins - Plugins with some extended statistics.
Mate - Meta Analysis and Tracing Engine - user configurable extension(s) of the display filter engine, see http://wiki.ethereal.com/Mate for details.
SNMP MIBs - SNMP MIBs for a more detailed SNMP dissection.
The Tools:
Editcap - Editcap is a program that reads a capture file and writes some or all of the packets into another capture file.
Text2Pcap - Text2pcap is a program that reads in an ASCII hex dump and writes the data into a libpcap-style capture file.
Mergecap - Mergecap is a program that combines multiple saved capture files into a single output file.
Capinfos - Capinfos is a program that provides information on capture files.
The Additional Tasks:
Start Menu Shortcuts - add some start menu shortcuts.
Desktop Icon - add an Ethereal icon to the desktop.
Quick Launch Icon - add an Ethereal icon to the Explorer quick launch toolbar.
Associate file extensions to Ethereal - Associate standard network trace files to Ethereal.
As mentioned above, the Ethereal installer includes WinPcap.
While running, the Ethereal installer detects which WinPcap version is currently running and will install WinPcap, if none or an older version is detected. So the following is only necessary if you want to try a different than the recommended WinPcap version, e.g. because a new WinPcap beta version was released.
You will find a single installer exe called something like "auto-installer", which can be installed under various Windows systems, including 9x/Me/NT4.0/2000/XP. This installer is located at: http://www.winpcap.org/install/default.htm.
Current information about the Ethereal related usage of WinPcap can be found at: http://wiki.ethereal.com/WinPcap
From time to time you may want to update your installed Ethereal to a more recent version. If you join Ethereal's announce mailing list, you will be informed about new Ethereal versions, see Section 1.7.4, “Mailing Lists” for details how to subscribe to this list.
Update Ethereal. New versions of Ethereal usually become available every 4-8 weeks. Updating Ethereal is done the same way as installing it, you simply download and start the installer exe. A reboot is usually not required and all your personal settings remain unchanged.
Update WinPcap. New versions of WinPcap are less frequently available, maybe only once a year. You will find WinPcap update instructions where you can download new versions. Usually you have to reboot the machine after installing a new WinPcap version.