Get in Touch

Course Outline

Network analysis overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark
  4. Understanding Wireshark: Portable version and resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
  6. Architecture and processing flow. Limitations of what can be seen with Wireshark.
  7. Supported protocols and dissectors.
  8. Preferences and configurations: global settings versus profile-specific options.
  9. Time value management.
  10. Lab exercises.

Capture traffic

  1. Key considerations before beginning.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture capabilities.
  6. Lab exercises.

Traffic analysis: tools and approaches

  1. Analysis checklist.
  2. Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
  3. Understanding the Expert System.
  4. Accessing options via Right-Click functionality.
  5. Interpretation (reference patterns) and the impact of OS/driver offload features.
  6. Saving results.
  7. Lab exercises and case studies.


Traffic analysis: tools and approaches (cont.)

  1. Filtering traffic: Display filters (preparing "in-flight" filters, macros) and following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packets Lengths, IP-specific metrics.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic analysis: protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP, UDP.
    1. Packet loss and recovery mechanisms.
    2. Events involving lost previous segments and out-of-order segments.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window issues, window changes, and other window-related problems.
  4. Application Layer: HTTP, FTP.
  5. Lab exercises and case studies.

Traffic analysis: common issues in network performance assessment

  1. Causes of performance problems.
  2. Packet loss.
  3. Bandwidth issues: A layered approach to measurement.
  4. Latency: Assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, tcpdump
    2. editcap, mergecap, capinfos, text2pcap.

Advanced topics

  1. Advanced filters and grouped I/O statistics.
  2. Summary and Q&A session.

Requirements

1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental knowledge of Unix/Linux operating systems, including: UNIX terminal usage, directory structures, listing files and directories, creating and navigating directories, copying, moving, and deleting files and directories, redirection, pipes, and managing processes (listing suspended and background processes).

Hardware & Software Requirements: 1. Hardware: Minimum 16GB of RAM and at least 60GB of available disk space.
2. Operating System: Ubuntu Linux is preferred. Ensure the following applications are installed: ip,
iperf, and ipcalc.
3. Software: Wireshark application (https://www.wireshark.org/download.html).

All components should be running the latest stable releases available.
 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories