My packets, let me show you them

Posted by stretch in Announcements on Monday, 30 Jun 2008 at 12:59 a.m. GMT

Earlier this month I mentioned the Wireshark wiki's capture page was a great place to find various packet captures, but it is sorely lacking in structure (not to mention security). Inspired, I decided to piece together my own capture repository.

At the time of this writing, the archive contains fifty captures of various traffic types, with a heavy focus on routing protocols. Captures can be organized by category or included protocol, with a healthy amount of overlap. Many captures include a simple topology to aid in setting context (look for a 'view topology' link under each capture). An RSS feed lists the most recent captures, and leeching is supported.

Yes, there are already places to find packets, like the aforementioned Wireshark wiki page or OpenPacket.org. But I wanted a structured, custom format with an emphasis on networking, not applications. This capture database was designed to serve as a reference, particularly to save engineers the hassle of setting up an entire lab merely to generate a protocol header. Hopefully people will find these captures useful. Let me know what you think!

Please note that I am not currently accepting outside captures or requests for captures, although support is likely to be added in the future. I still have a quite a few captures to generate and upload, so be sure to check back once in a while.

Richard Bannister commented on 30 Jun 2008 at 11:49 a.m.

Absolutely Superb! :-)

I don't want to know how long it has taken you to put that collection together! (inc. diagrams)

Richard

nemako commented on 2 Jul 2008 at 3:24 p.m.

Hi, thanks for that collection, it could be very usefull.

Just a remark, there is a bug with firefox on the protocols lists on the left :)

Thanks again for your website...

Tassos commented on 8 Jul 2008 at 5:11 p.m.

Excellent idea! I really needed the mcast ones.

Leave a comment

(optional) (will not be published)
(optional)