Get in Touch
 Duration 35 hours

Course Outline

Network analysis overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark
  4. What is Wireshark? Portable Wireshark and available resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and processing flow: What Wireshark cannot see and why.
  7. Supported protocols and dissectors.
  8. Preferences and configurations, both global and profile-specific.
  9. Time value interpretation.
  10. Lab exercises.

Capture traffic

  1. Pre-capture considerations.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture.
  6. Lab exercises.

Traffic analysis: tools and approaches

  1. Analysis checklist.
  2. Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
  3. Understanding the Expert System.
  4. Accessing options via right-click functionality.
  5. Interpretation: reference patterns and the impact of OS/driver offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic analysis: tools and approaches (continued)

  1. Filtering traffic: Display filters (including "in-flight" filters and macros) and stream following.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic analysis: protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Previous segment lost and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window changes, and other window-related issues.
  4. Application layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic analysis: common issues in network performance assessment

  1. Identifying causes of performance problems.
  2. Packet loss analysis.
  3. Bandwidth issues and a layered approach to measurement.
  4. Latency: assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. Command-line tools for Wireshark:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced topics

  1. Advanced filters and grouped iostats.
  2. Summary and Q&A.

Requirements

1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Foundational knowledge of Unix/Linux operating systems: UNIX terminal usage, directory structures, file and directory listing, creation, navigation, copying, moving, and deletion, as well as redirection, pipes, and process management (including listing suspended and background processes).

Hardware & Software Requirements
1. HW: A minimum of 16GB RAM and 60GB of free disk space is required.
2. OS: Ubuntu Linux OS is recommended. If using this OS, ensure the following applications are installed: ip, iperf, and ipcalc.
3. SW: The Wireshark application (https://www.wireshark.org/download.html).

All software should be updated to the latest stable release available.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 8000 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (3)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories