On Monday 09 February 2004 07:34, Hampus Linden wrote: > Ethereal is good if "realtime" stuff. But for the "trapped" stuff I > use Snort. Check it out at http://www.snort.org/ > > I'll echo the "snort" recommendation. In addition you may just want to capture your traffic using tcpdump as most other software is able to read tcpdump capture files. With this, you can start capturing immediately and evaulate software at your leisure using the same data. Regards, Mike Klinke