By stretch | Monday, June 30, 2008 at 12:59 a.m. UTC

Earlier this month I mentioned the Wireshark wiki's capture page was a great place to find various packet captures, but it is sorely lacking in structure (not to mention security). Inspired, I decided to piece together my own capture repository.

At the time of this writing, the archive contains fifty captures of various traffic types, with a heavy focus on routing protocols. Captures can be organized by category or included protocol, with a healthy amount of overlap. Many captures include a simple topology to aid in setting context (look for a 'view topology' link under each capture). An RSS feed lists the most recent captures, and leeching is supported.

Yes, there are already places to find packets, like the aforementioned Wireshark wiki page or But I wanted a structured, custom format with an emphasis on networking, not applications. This capture database was designed to serve as a reference, particularly to save engineers the hassle of setting up an entire lab merely to generate a protocol header. Hopefully people will find these captures useful. Let me know what you think!

Please note that I am not currently accepting outside captures or requests for captures, although support is likely to be added in the future. I still have a quite a few captures to generate and upload, so be sure to check back once in a while.

Richard Bannister (guest)
June 30, 2008 at 11:49 a.m. UTC

Absolutely Superb! :-)

I don't want to know how long it has taken you to put that collection together! (inc. diagrams)


nemako (guest)
July 2, 2008 at 3:24 p.m. UTC

Hi, thanks for that collection, it could be very usefull.

Just a remark, there is a bug with firefox on the protocols lists on the left :)

Thanks again for your website...

Tassos (guest)
July 8, 2008 at 5:11 p.m. UTC

Excellent idea! I really needed the mcast ones.

