Course Outline
Overview of Network Analysis
- Essentials of the OSI reference model and TCP/IP networking.
- Available troubleshooting tools and effective methodologies.
- Getting started with Wireshark
- Introduction to Wireshark: Portable version features and available resources.
- Understanding the Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- Internal architecture and processing flow; understanding the limitations of what Wireshark can visualize.
- Overview of supported protocols and dissectors.
- Configuring preferences: global settings versus profile-specific adjustments.
- Interpreting time values in captures.
- Practical lab exercises.
Traffic Capture
- Key considerations prior to initiating a capture.
- Understanding Promiscuous mode.
- Implementing capture filters.
- Setting automatic stop criteria.
- Performing remote captures.
- Hands-on lab exercises.
Traffic Analysis: Tools and Methodologies
- Developing a comprehensive analysis checklist.
- Leveraging built-in features: name resolution, colorization, marking, ignoring packets, adding comments, utilizing time references, and applying time shifts.
- Mastering the Expert Information system.
- Navigating options via Right-Click functionality.
- Interpreting data based on reference patterns and assessing the impact of OS/driver Offload features.
- Exporting and saving analysis results.
- Lab exercises and case study walkthroughs.
Traffic Analysis: Tools and Methodologies (Continued)
- Filtering traffic: Utilizing Display filters (including pre-configured "in-flight" filters and macros) and following data streams.
- Quantitative analysis.
- Reviewing basic predefined statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Conducting protocol-specific analysis (e.g., TCP Stream Graphs).
- Generating advanced custom statistics using I/O Graphs.
- Visualizing data flow.
Traffic Analysis: Protocol Deep Dive
- Data-Link Layer: Focus on Ethernet II.
- Network Layer: Focus on IPv4.
- Transport Layer: In-depth analysis of TCP and UDP.
- Diagnosing packet loss and recovery mechanisms.
- Analyzing Previous Segment Lost and Out-of-Order Segments events.
- Investigating Duplicate ACKs and Fast Retransmissions.
- Understanding TCP Retransmissions.
- Resolving Zero Window, window scaling changes, and other window-related issues.
- Application Layer: Analysis of HTTP and FTP.
- Lab exercises and applied case studies.
Traffic Analysis: Common Challenges in Network Performance Assessment
- Identifying root causes of performance degradation.
- Analyzing packet loss patterns.
- Addressing bandwidth constraints using a layered measurement approach.
- Evaluating latency: assessing end-to-end delays and visualization techniques.
- Practical lab exercises.
- (Wireshark) Command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced Topics
- Implementing advanced filters and grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Foundational understanding of Unix/Linux operating systems, including UNIX terminal usage, directory structures, file and directory management (listing, creating, navigating, copying, moving, and deleting), redirection, piping, and process management (listing suspended and background processes).
Hardware & Software Requirements
1. Hardware: A minimum of 16GB RAM and 60GB of free disk space is required.
2. Operating System: Ubuntu Linux is the recommended platform. Ensure the following applications are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (available at https://www.wireshark.org/download.html).
All software components should be updated to the latest stable releases.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge