Course Outline
Network analysis overview
- Essentials of the OSI reference model and TCP/IP networks.
- Overview of troubleshooting tools and methodologies.
- Introduction to Wireshark
- Understanding Wireshark: Portable versions and available resources.
- Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- Architecture and processing flow: Identifying limitations of what can be observed.
- Supported protocols and dissectors.
- Configuring preferences and settings: Global and profile-specific options.
- Interpreting time values.
- Practical lab exercises.
Capturing traffic
- Pre-capture considerations and best practices.
- Utilizing Promiscuous mode.
- Implementing capture filters.
- Setting automatic stop criteria.
- Performing remote captures.
- Practical lab exercises.
Traffic analysis: tools and approaches
- Developing an analysis checklist.
- Leveraging key features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Accessing options via Right-Click functionality.
- Data interpretation (reference patterns) and the impact of OS/driver Offload features.
- Saving and exporting results.
- Lab exercises and case studies.
Traffic analysis: tools and approaches (continued)
- Filtering traffic: Display filters (creating "in-flight" filters, macros), and following streams.
- Quantitative analysis.
- Basic predefined statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery mechanisms.
- Handling Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes, and other window-related issues.
- Application layer: HTTP and FTP.
- Lab exercises and case studies.
Traffic analysis: common issues in network performance assessment
- Identifying root causes of performance problems.
- Analyzing packet loss.
- Addressing bandwidth issues through a layered measurement approach.
- Latency: Assessing end-to-end latency and visualizing data.
- Practical lab exercises.
- Wireshark command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental proficiency in Unix/Linux operating systems, including UNIX terminal commands, directory structure navigation, file and directory management (listing, creating, changing, copying, moving, and deleting), as well as working with redirection, pipes, and process management (listing suspended and background processes).
Hardware & Software Requirements
1. HW: Minimum 16GB of RAM and at least 60GB of available disk space.
2. OS: Ubuntu Linux OS is recommended. If using this environment, ensure the following utilities are installed: ip, iperf, and ipcalc.
3. SW: The Wireshark application (available at https://www.wireshark.org/download.html).
All software components should be updated to the latest stable releases.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge