nettbswsadv Advanced Network Troubleshooting Using Wireshark 21 hours This course is a continuation of the "Basic Network Troubleshooting Using Wireshark" course, and comes to provide the participants with advanced capabilities for network troubleshooting. The course provides an in-depth knowledge of network behaviour and problems, along with the capabilities to isolate and solve security and advanced applications problems. The course is based on theory, class exercise and labs. Command-Line Tools and How to Use Them TShark and Dumpcap Command-Line Tools Capinfos Command-Line Tool Editcap Command-Line Tool Mergecap Command-Line Tool Text2pcap Command-Line Tool Split and Merge Trace Files Advance usage of Capture and Display Filters Writing advanced Capture filters scripts Writing Advanced Display filters Using triggered filters The Expert System Advance Usage Dealing with congestion - shattered windows and flooding Baseline network communications Unusual network communications Vulnerabilities in the TCP/IP resolution process Lab exercises and case studies Who is talking? Port Scans Mutant Scans IP Scans Application Mapping OS Fingerprinting Lab exercises and case studies VoIP Analysis SIP analysis and troubleshooting RTP, RTCP and media analysis Creating VoIP filters and analysis profiles Lab exercises and case studies Applications Analysis and Troubleshooting HTTP analysis and troubleshooting FTP analysis and troubleshooting DNS operation and troubleshooting Video transmission analysys Databases network-related problems Network Security and Forensics Basics Gather information – what to look for Unusual traffic patterns Complementary tools Detecting Security Suspicious Patterns MAC and IP address spoofing Attacks signatures and signature locations ARP poisoning Header and sequencing signatures Attacks and exploits TCP splicing and unusual traffic DoS and DDoS Attacks Protocol scans maliciously malformed packets Lab exercises and case studies
nettbsws Basic Network Troubleshooting Using Wireshark 21 hours The purpose of the course is to provide the participant with basic knowledge of the Wireshark protocol analyzer. The course focuses on deep understanding of the tool, as the basics for using it for network troubleshooting. The course starts with packet capturing, capture and display filters, statistical features and the basics of the expert system. By the end of the course the participant will be able to perform basic troubleshooting in small to medium size networks. The course is based on theory, class exercise and labs. Introduction to network troubleshooting What is network troubleshooting Troubleshooting tools Troubleshooting methodologies Introduction to Wireshark How Wireshark Works Capturing Packets, What are capture and display filters Configuring Global Preferences Navigation and Colorization Techniques Using Time Values and Summaries Examining Basic Trace File Statistics Save, Export and Print Capture and Display Filters Capture filters – basics and filter language Display filters – basics and filter language Useful filters Lab exercises and case studies Using Time Values and Summaries Use the default time column setting and precision Use time between packets Set a time reference and view capture times Troubleshooting timing problems Lab exercises and case studies Using Statistics Tools Create I/O graphs Create TCP Time-Sequence graphs Analyze flow graphs Evaluate service response times Create Round-Trip-Time graphs Analyze TCP/IP flows Analyse applications flows Lab exercises and case studies The Expert System Basics Normal and un-normal Network Communications Causes of Performance Problems Packet Losses, Ack to longs and Retransmissions Lab and case studies Bandwidth Issues Bandwidth measurement User/flow throughput calculations Applications throughput calculations Bandwidth and throughput problems Lab exercises and case studies Latency Issues The primary points in calculating latency Plotting high latency times Free latency calculators Using the frame.time_delta filter Lab exercises and case studies Packet Loss and Retransmissions Packet loss and recovery - UDP and TCP Previous segment lost and Out-of-Order Segments events Duplicate ACKs and Fast Retransmissions TCP Retransmissions Zero window, Window changes and other window problems Lab exercises and case studies

