Course Outline
Network analysis overview
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark.
- Understanding Wireshark, including Portable Wireshark and available resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
- Architecture and processing flow, including visibility limitations.
- Supported protocols and dissectors.
- Preferences and configurations, both global and profile-specific.
- Handling time values.
- Lab exercises.
Capture traffic
- Pre-capture considerations.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture.
- Lab exercises.
Traffic analysis: tools and approaches
- Analysis checklist.
- Utilizing features such as name resolution, colorization, marking, ignoring, commenting, and time references.
- Understanding the Expert System.
- Accessing options via Right-Click functionality.
- Interpretation of reference patterns and the impact of OS/driver Offload features.
- Saving results.
- Lab exercises and case studies.
Traffic analysis: tools and approaches (cont.)
- Filtering traffic: Display filters (including 'in-flight' filters and macros), and following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery.
- Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes, and other window-related problems.
- Application layer: HTTP and FTP.
- Lab exercises and case studies.
Traffic analysis: common issues in network performance assessment
- Root causes of performance problems.
- Packet loss.
- Bandwidth issues and layered approaches to measurement.
- Latency: assessing and visualizing end-to-end latency.
- Lab exercises.
- Wireshark command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental knowledge of Unix/Linux operating systems, including UNIX terminal usage, directory structures, file and directory management (listing, creating, changing, copying, moving, and removing), as well as redirection, pipes, and process management (listing suspended and background processes).
Hardware & Software
1. Hardware: Minimum 16GB of RAM and at least 60GB of available free disk space.
2. OS: Ubuntu Linux OS is recommended. Ensure the following applications are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All tools should be updated to the latest stable releases.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge