Course Outline
Network Analysis Fundamentals
- Core concepts of the OSI reference model and TCP/IP networking.
- Overview of troubleshooting tools and systematic methodologies.
- Introduction to Wireshark capabilities
- Understanding Wireshark: Portable versions and available resources.
- Interface layout: Packet List, Details, Packet Bytes panes, and Status Bar.
- Architecture and data processing flow, including visibility limitations.
- Overview of supported protocols and dissectors.
- Configuring preferences, including global and profile-specific settings.
- Interpreting time values within captures.
- Practical laboratory exercises.
Traffic Capture Techniques
- Key considerations prior to initiating a capture session.
- Understanding and utilizing Promiscuous mode.
- Applying capture filters to optimize data collection.
- Setting automatic stop conditions for captures.
- Performing remote packet captures.
- Practical laboratory exercises.
Traffic Analysis: Tools and Methodologies
- Developing a structured analysis checklist.
- Leveraging analysis features: name resolution, colorization, marking, ignoring, commenting, and time reference tools.
- Interpreting the Expert Information system.
- Utilizing context menu options via right-click functionality.
- Analyzing reference patterns and assessing the impact of OS/driver Offload features.
- Exporting and saving analysis results.
- Lab exercises and real-world case studies.
Traffic Analysis: Tools and Methodologies (Continued)
- Refining traffic visibility: Display filters (creating "in-flight" filters, using macros), and following data streams.
- Quantitative data analysis.
- Reviewing predefined statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Conducting protocol-specific analysis (e.g., TCP Stream Graphs).
- Utilizing I/O Graphs for advanced custom statistics.
- Visualizing network flows.
Traffic Analysis: Protocol Deep Dive
- Data-Link Layer: Focusing on Ethernet II.
- Network Layer: Analyzing IPv4.
- Transport Layer: Examining TCP and UDP behaviors.
- Monitoring packet loss and recovery mechanisms.
- Identifying Previous Segment Lost and Out-of-Order Segments events.
- Diagnosing Duplicate ACKs and Fast Retransmissions.
- Analyzing TCP Retransmissions.
- Investigating Zero Window conditions, window adjustments, and related flow control issues.
- Application Layer: Inspecting HTTP and FTP traffic.
- Lab exercises and case study applications.
Traffic Analysis: Addressing Common Performance Issues
- Identifying root causes of performance degradation.
- Analyzing packet loss impacts.
- Addressing bandwidth constraints using a layered measurement approach.
- Measuring and visualizing end-to-end latency.
- Practical laboratory exercises.
- Utilizing (Wireshark) command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced Concepts
- Applying advanced filters and grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Foundational proficiency in Unix/Linux operating systems, including terminal usage, directory navigation, file management (listing, creating, copying, moving, and deleting), command redirection, pipes, and process monitoring (including suspended and background tasks).
Hardware & Software
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All software components should be updated to the latest stable releases available.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge