Course Outline
Network analysis overview
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark
- What is Wireshark? Portable Wireshark and available resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- Architecture and processing flow: What Wireshark cannot see and why.
- Supported protocols and dissectors.
- Preferences and configurations, both global and profile-specific.
- Time value interpretation.
- Lab exercises.
Capture traffic
- Pre-capture considerations.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture.
- Lab exercises.
Traffic analysis: tools and approaches
- Analysis checklist.
- Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Accessing options via right-click functionality.
- Interpretation: reference patterns and the impact of OS/driver offload features.
- Saving analysis results.
- Lab exercises and case studies.
Traffic analysis: tools and approaches (continued)
- Filtering traffic: Display filters (including "in-flight" filters and macros) and stream following.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery mechanisms.
- Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, window changes, and other window-related issues.
- Application layer: HTTP and FTP.
- Lab exercises and case studies.
Traffic analysis: common issues in network performance assessment
- Identifying causes of performance problems.
- Packet loss analysis.
- Bandwidth issues and a layered approach to measurement.
- Latency: assessing end-to-end latency and visualization techniques.
- Lab exercises.
- Command-line tools for Wireshark:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced topics
- Advanced filters and grouped iostats.
- Summary and Q&A.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Foundational knowledge of Unix/Linux operating systems: UNIX terminal usage, directory structures, file and directory listing, creation, navigation, copying, moving, and deletion, as well as redirection, pipes, and process management (including listing suspended and background processes).
Hardware & Software Requirements
1. HW: A minimum of 16GB RAM and 60GB of free disk space is required.
2. OS: Ubuntu Linux OS is recommended. If using this OS, ensure the following applications are installed: ip, iperf, and ipcalc.
3. SW: The Wireshark application (https://www.wireshark.org/download.html).
All software should be updated to the latest stable release available.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 8000 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge