The world`s foremost network protocol analyzer for Mac

Wireshark for Mac

Wireshark 2.1.0

  -  30.8 MB  -  Open Source

Sometimes latest versions of the software can cause issues when installed on older devices or devices running an older version of the operating system.

Software makers usually fix these issues but it can take them some time. What you can do in the meantime is to download and install an older version of Wireshark 2.1.0.


For those interested in downloading the most recent release of Wireshark for Mac or reading our review, simply click here.


All old versions distributed on our website are completely virus-free and available for download at no cost.


We would love to hear from you

If you have any questions or ideas that you want to share with us - head over to our Contact page and let us know. We value your feedback!

  • Wireshark 2.1.0 Screenshots

    The images below have been resized. Click on them to view the screenshots in full size.

    Wireshark 2.1.0 Screenshot 1
  • Wireshark 2.1.0 Screenshot 2
  • Wireshark 2.1.0 Screenshot 3
  • Wireshark 2.1.0 Screenshot 4

What's new in this version:

NEW AND UPDATED FEATURES:
- You can now switch between between Capture and File Format dissection of the current capture file via the View menu in the Qt GUI
- You can now show selected packet bytes as ASCII, HTML, Image, ISO 8859-1, Raw, UTF-8, a C array, or YAML
- You can now use regular expressions in Find Packet and in the advanced preferences
- Name resolution for packet capture now supports asynchronous DNS lookups only. Therefore the "concurrent DNS resolution" preference has been deprecated and is a no-op. To enable DNS name resolution some build dependencies must be present (currently c-ares). If that is not the case DNS name resolution will be disabled (but other name resolution mechanisms, such as host files, are still available)
- The byte under the mouse in the Packet Bytes pane is now highlighted
- TShark supports exporting PDUs via the -U flag
- The Windows and OS X installers now come with the "sshdump" and "ciscodump" extcap interfaces
- Most dialogs in the Qt UI now save their size and positions
- The Follow Stream dialog now supports UTF-16
- The Firewall ACL Rules dialog has returned
- The Flow (Sequence) Analysis dialog has been improved

MAJOR API CHANGES::
- The address macros (e.g., SET_ADDRESS) have been removed. Use the (lower case) functions of the same names instead.
- "old style" dissector functions (that don't return number of bytes used) have been replaced in name with the "new style" dissector functions.
- tvb_get_string and tvb_get_stringz have been replaced with tvb_get_string_enc and tvb_get_stringz_enc respectively.

NEW FILE FORMAT DECODING SUPPORT:
Wireshark is able to display the format of some types of files (rather than displaying the contents of those files). This is useful when you're curious about, or debugging, a file and its format. To open a capture file (such as PCAP) in this mode specify "MIME Files Format" as the file's format in the Open File dialog. New files that Wireshark can open in this mode include:

NEW PROTOCOL SUPPORT:
- Apache Cassandra - CQL version 3.0, Bachmann bluecom Protocol, Bluetooth Pseudoheader for BR/EDR, CISCO ERSPAN3 Marker, Edge Control Protocol (ECP), Ericsson IPOS Kernel Packet Header Dissector Added (IPOS), Extensible Control & Management Protocol (eCMP), FLEXRAY Protocol dissector added (automotive bus), ISO 8583-1, ISO14443, ITU-T G.7041/Y.1303 Generic Framing Procedure (GFP), LAT protocol (DECNET), Metamako trailers, Nokia Intelligent Service Interface (ISI), Open Mobile Alliance Lightweight Machine to Machine TLV payload Added (LwM2M TLV), RTI TCP Transport Layer (RTITCP), STANAG 5602 SIMPLE, USB3 Vision Protocol (USB machine vision cameras), USBIP Protocol, UserLog Protocol, and Zigbee Protocol Clusters Dissectors Added (Closures Lighting General Measurement & Sensing HVAC Security & Safety)

UPDATED PROTOCOL SUPPORT:
- Bluetooth OBEX dissector (btobex) was renamed to Obex Dissector (obex), allow to DecodeAs it over USB, TCP and UDP. A preference was added to TCP dissector for handling IPFIX process information. It has been disabled by default