depends. For Redhat, I would capture in tcpdump and then open offline (ethereal is a huge security hole, and not always stable). For opening large captures/applying filters to large captures, it's all about the memory. I have 2 GB, and still have 20 minute filtering times...of course, that's a 2-5GB capture file (sometimes larger)...