Course Outline
Overview of Network Analysis
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark
- Understanding Wireshark: Portable versions and available resources.
- Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- Architecture and processing flow: limitations and invisible elements in Wireshark.
- Supported protocols and dissection methods.
- Preferences and configurations, both global and profile-specific.
- Handling time values.
- Lab exercises.
Capturing Traffic
- Pre-capture considerations.
- Promiscuous mode.
- Setting capture filters.
- Defining automatic stop criteria.
- Remote capture techniques.
- Lab exercises.
Traffic Analysis: Tools and Methodologies
- Analytical checklists.
- Leveraging features: name resolution, color-coding, marking, ignoring, commenting, and time references/shifts.
- Comprehending the Expert System.
- Accessing options via Right-Click functionality.
- Interpretation using reference patterns and the impact of OS/driver Offload features.
- Saving analysis results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Methodologies (Continued)
- Filtering traffic: Display filters (preparing "in-flight" filters, macros) and following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic Analysis: Protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery mechanisms.
- Events involving lost previous segments and Out-of-Order Segments.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, window size changes, and other window-related issues.
- Application Layer: HTTP and FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Root causes of performance issues.
- Packet loss analysis.
- Bandwidth issues and layered measurement approaches.
- Latency: Assessing end-to-end latency and visualization techniques.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based Wireshark) / dumpcap / rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced Topics
- Advanced filters and grouped iostats.
- Summary and Q&A session.
Requirements
1. Understanding of the ISO OSI Reference Model - ITU-T X.200 and the TCP/IP protocol stack.
2. Foundational knowledge of Unix/Linux operating systems: UNIX terminal usage, directory structure, listing files and directories, creating directories, navigating paths, copying, moving, and deleting files and directories, redirection, pipes, and managing suspended and background processes.
Hardware & Software
1. HW: Minimum 16GB of RAM and 60GB of free disk space.
2. OS: Ubuntu Linux OS is recommended. If used, ensure the following applications are installed: ip, iperf, ipcalc.
3. SW: Wireshark application (https://www.wireshark.org/download.html).
All components should be running the latest stable available releases.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge