Since Ethereal® was renamed to Wireshark® in May 2006,
many new features have been added, and protocol support has
continued at its usual breakneck pace. Several important bugs
have been fixed as well. A complete list of updates for each
version of Wireshark can be found in the release notes. The top ten reasons to switch are
- Wireshark is under active development. It receives security
updates and new features.
- Wireshark supports full 802.11 capture on Windows when
used with AirPcap.
- VoIP call playback.
- Decryption support has been added and updated for
- Keyboard navigation is much easier, and the packet
list context menu has many more features.
- Wireshark is available as a U3 package.
- Windows support has been greatly improved.
- Expert analysis has been expanded.
- Wireshark lets you export HTTP objects.
- Display filters are more powerful, with the addition of
macros, upper(), and lower().
Migrating from Ethereal to Wireshark is a long and arduous
process. A typical migration project requires the following
- 1 (one) project manager (PMP certification preferred)
- 1 (one) assistant project manager
- 2 (two) pirate hats
- 2 (two) system administrators
- 1 (one) duck
- 2 (two) network administrators
- 4 (four) support staff
- 2 (three) bags of hammers
If you allocate full-time staff to the migration, it can take as
little as six weeks for preparation and planning, and four weeks
for the migration itself. Past migrations have resulted in some
maiming and blood loss. A recent survey of human resources
directors found that the amounts were within acceptable
The complete migration procedure is detailed below:
- Place the pirate hats near the project manager, assistant project
manager, and system administrators. Allow time for them to start
fighting over the hats (about 3.5 seconds).
- Place the duck on top of a core switch and allow it to nest.
- Casually mention to a support person that you heard a quacking
noise near the data center. Allow time for word to get to the
network administrators, and for the support staff to gather
together to watch the spectacle.
- To ensure that you're not disturbed, keep the bags of hammers
nearby and maintain a stern expression.
- Uninstall Ethereal.
- Install Wireshark.
Note: Steps 5 and 6 should take about three minutes.