Wireshark

You paid for a gigabit line, your router says gigabit, your PC says gigabit, and somehow every large download tops out at 11 MB/s. The invisible culprit is almost always physical: a bent RJ45 connector, a flat “gigabit” cable rolled up too tight behind a desk, a wall plate wired with only four of the eight pins, or a switch port that quietly renegotiated to 100 Mbps two months ago. Nothing on your desktop pops a warning. Everything just feels slow. The best apps for diagnosing Ethernet problems can tell you within a few minutes whether the fault sits in the cable, the switch, the network stack, the driver, or upstream at the ISP. Below are eight desktop tools we keep on every workstation and homelab, ranging from packet-level captures to long-term latency graphs, all runnable without special hardware.

What to look for in a network diagnostic tool

A good diagnostic app covers at least two of these five bases, and the strongest ones cover three or four:

Quick comparison

App Best for Platforms Free plan Starting price License
Wireshark Deep packet capture Windows, macOS, Linux Yes (full) Free GPL-2.0
iperf3 Raw throughput between two hosts Windows, macOS, Linux, BSD Yes (full) Free BSD-3
PingPlotter Visual hop-by-hop latency Windows, macOS Yes (limited) Around 40 USD/year Proprietary
NetSpot Wi-Fi and mixed-network site surveys Windows, macOS Yes (limited) Around 50 USD Proprietary
Fing Desktop Fast GUI scan of every device on the LAN Windows, macOS Yes Around 30 USD/year Proprietary
Nmap Port scanning, service fingerprinting Windows, macOS, Linux Yes (full) Free GPL-2.0
SmokePing Long-term latency and packet-loss graphs Linux (server), any browser Yes (full) Free GPL-2.0
LAN Speed Test Point-and-click LAN throughput Windows, macOS Yes (limited) Around 10 USD Proprietary

The apps

1. Wireshark

Wireshark is the reference implementation of a packet analyzer. Capture on any interface, drill down through every layer of every frame, and filter with expressions that stay readable a year later. When a VoIP call stutters or a printer stops answering, Wireshark shows you the retransmissions, the ARP storms, the mystery multicast, and the TCP window collapses that no throughput test will ever surface.

Weaknesses: the interface is dense on first launch, and captures on a switched network only see broadcast traffic and your own frames unless you set up a mirror port. Live capture on Windows still needs Npcap.

Pricing: free and open source under GPL-2.0.

Platforms: Windows, macOS, Linux.

Download: Wireshark

Bottom line: if the numbers look fine but one specific application misbehaves, Wireshark is the only tool on this list that can tell you why.

2. iperf3

iperf3 measures raw throughput between two hosts. Install it on both ends, run one as a server, one as a client, and within seconds you get a clean readout in megabits per second, with jitter and loss on UDP tests. It ignores the internet entirely and tells you what your own cable, switch, and NIC can actually do.

Weaknesses: single-threaded by default (use -P 4 on 10 Gbps links), no GUI, and results depend on the CPU at both ends being fast enough not to bottleneck.

Pricing: free and open source under BSD-3.

Platforms: Windows, macOS, Linux, BSD.

Download: iperf3

Bottom line: the fastest way to prove whether a suspect cable, port, or wall plate is negotiating gigabit or falling back to 100 Mbps.

3. PingPlotter

PingPlotter runs a continuous traceroute and plots the latency to every hop over time. Packet loss lights up in red at whichever router is dropping frames, so you can tell within minutes whether the problem is your own switch, the last-mile fiber, or a specific peering point three hops away.

Weaknesses: the free tier caps the number of targets and history depth. The paid Standard tier is a yearly subscription rather than a one-time purchase.

Pricing: free tier available; Standard around 40 USD per year, Professional higher.

Platforms: Windows, macOS.

Download: PingPlotter

Bottom line: the clearest visual proof that a slowdown lives on your ISP’s network, not on your desk.

4. NetSpot

NetSpot is a site survey tool. Walk around with a laptop and it builds a heatmap of signal strength, interference, and channel use. On a wired-plus-wireless network it also spots the moment devices roam off Ethernet-backed access points onto a weaker one and start driving mysterious latency.

Weaknesses: the free tier is limited to a small number of survey points and hides the deeper analytics behind the paid upgrade. Primarily a Wi-Fi tool, so it complements rather than replaces the cable-focused apps above.

Pricing: free tier available; Home upgrade around 50 USD as a one-off.

Platforms: Windows, macOS.

Download: NetSpot

Bottom line: rules out Wi-Fi as the invisible bottleneck when everyone assumes it must be the Ethernet.

5. Fing Desktop

Fing Desktop scans your LAN in seconds and lists every device with vendor, IP, MAC, and open ports. New devices trigger a notification, and the built-in internet speed and outage monitoring runs in the background so you have a record next time your uplink hiccups.

Weaknesses: the free version covers the basics; deeper alerts, Wi-Fi analysis, and multi-network dashboards live behind the Premium subscription. Account signup is required for most of the good features.

Pricing: free tier; Premium around 30 USD per year.

Platforms: Windows, macOS.

Download: Fing Desktop

Bottom line: the fastest GUI answer to “what is that thing on my network and when did it show up”.

6. Nmap

Nmap is the classic network scanner. Point it at a subnet and it maps every reachable host, guesses the operating system, and probes open services. When a device is misbehaving because a firewall silently blocks port 445 or a printer daemon crashed, Nmap tells you before you spend an hour blaming the cable.

Weaknesses: unfiltered scans on a corporate network will attract attention. The syntax has grown deep over 25 years, and the Zenmap GUI is only a partial substitute for the CLI.

Pricing: free and open source under a modified GPL-2.0.

Platforms: Windows, macOS, Linux.

Download: Nmap

Bottom line: the standard for figuring out what is actually reachable on your LAN and whether services are answering.

7. SmokePing

SmokePing graphs latency and packet loss to a set of targets over days and weeks. It runs as a small server, usually on a Linux box or a NAS, and paints the noise around each ping as a fuzzy grey band, so intermittent problems that never show up during a five-minute test become impossible to miss.

Weaknesses: setup involves Perl, a web server, and RRDtool, and the default look is uncompromisingly 2005. No native Windows or macOS server build, though the graphs are browser-based.

Pricing: free and open source under GPL-2.0.

Platforms: Linux (server), any modern browser for viewing.

Download: SmokePing

Bottom line: the only way to catch the packet-loss spike that hits your line for two minutes every night at 03:14.

8. LAN Speed Test

LAN Speed Test writes a file to a target folder on another machine or NAS and reads it back, reporting throughput in a plain dialog. No server daemon to install on the other end, which makes it useful for checking a shared drive or a specific SMB mount rather than raw network speed.

Weaknesses: the free version is limited; the paid Lite build unlocks larger tests and CSV logging. Results are influenced by the destination disk, so a slow NAS will look like a slow network.

Pricing: free tier; Lite around 10 USD as a one-off.

Platforms: Windows, macOS.

Download: LAN Speed Test

Bottom line: the quickest check that a specific file share is running at the speed the network allows.

How to pick the right one

Start with the question you are trying to answer. If you want to know whether your own LAN can push gigabit, run iperf3 between two machines on the same switch; it takes 30 seconds and settles most cable-vs-configuration arguments. If a single application misbehaves while everything else looks fine, capture the traffic in Wireshark and read the retransmissions and RSTs directly. When the ISP is under suspicion, leave PingPlotter running against a handful of upstream targets and let the red bars point at the guilty hop.

For a homelab or small office that wants to catch problems before users complain, install SmokePing on a spare box and graph a dozen targets around the clock. Use Fing Desktop for the quick GUI census of what is on the network today, Nmap when you need port-level detail, NetSpot when the Wi-Fi is entangled with the wired mess, and LAN Speed Test for a friendly click-and-see readout on a specific share. Nothing here is exclusive; the strongest setup runs iperf3 on demand, SmokePing continuously, and Wireshark whenever a specific complaint arrives.

FAQ

What is the best free option? For most Ethernet troubleshooting, iperf3 does the heaviest lifting for free: real throughput between two hosts, in seconds, with no telemetry. Pair it with Wireshark when you need to see the actual packets.

Can these apps test cable quality without a dedicated hardware tester? Not directly. A physical cable tester still wins for pinout and continuity. What these apps can do is prove the effect: if iperf3 caps at 94 Mbps between two gigabit-capable machines on the same switch, the cable, port, or wall plate is the problem, and a swap test will confirm which one.

Do they work over Wi-Fi? Yes. iperf3, Wireshark, PingPlotter, Nmap, and SmokePing treat Wi-Fi as just another interface. For radio-specific issues (signal strength, channel overlap, roaming) reach for NetSpot, which is built for that job.

Is Wireshark legal to use on a home network? On a network you own or administer, yes. Wireshark itself is a passive listener and does not send unsolicited traffic. Capturing other people’s traffic on a network you do not control is a different question and depends on local law and consent rules.

What is best for finding a bad cable? Run iperf3 between two known-good machines using the suspect cable, then swap the cable and run it again. A gigabit link that falls to 100 Mbps in one direction is almost always a wiring fault on one of the eight pins, and the throughput drop makes it obvious in one test.