Course Outline
Network analysis overview
- Essentials of the OSI reference model and TCP/IP networks.
- Methodologies and tools for troubleshooting.
- Introduction to Wireshark
- Understanding Wireshark: Portable Wireshark and resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
- Architecture and processing flow: Limitations of what can and cannot be seen with Wireshark.
- Supported protocols and dissectors.
- Preferences and configurations: global and profile-specific settings.
- Understanding time values.
- Lab exercises.
Capture traffic
- Key considerations before starting a capture.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture techniques.
- Lab exercises.
Traffic analysis: tools and approaches
- Analysis checklist.
- Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Navigating options via Right-Click functionality.
- Interpretation using reference patterns and understanding the impact of OS/driver Offload features.
- Saving results.
- Lab exercises and case studies.
Traffic analysis: tools and approaches (cont.)
- Filtering traffic: Display filters (creating 'in-flight' filters and macros), following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery mechanisms.
- Events for previously lost segments and out-of-order segments.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window scenarios, window changes, and other window-related issues.
- Application Layer: HTTP, FTP.
- Lab exercises and case studies.
Traffic analysis: common issues in network performance assessment
- Causes of performance problems.
- Packet loss.
- Bandwidth issues: A layered approach to measurement.
- Latency: Assessing end-to-end latency and visualization.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A.
Requirements
1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Basic knowledge of Unix/Linux OS: UNIX terminal commands, directory structures, listing files and directories, creating directories, navigating to different directories, copying, moving and removing files and directories, redirection, pipes, and managing processes (listing suspended and background processes).
Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux OS is preferred. The following applications should be installed: ip, iperf, ipcalc.
3. Software: Wireshark application (https://www.wireshark.org/download.html).
All software and system components should be the latest stable releases available.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge