Get in Touch

Course Outline

Overview of Network Analysis

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Standard troubleshooting tools and methodological approaches.
  3. Introduction to Wireshark.
  4. Understanding Wireshark: Portable version and key resources.
  5. Wireshark interface layout: Packet List, Details, Packet Bytes panes, and the Status Bar.
  6. Internal architecture and data processing flow; limitations of visibility in Wireshark.
  7. Supported protocols and dissectors.
  8. Managing preferences and configurations, both global and profile-specific.
  9. Understanding time values in captures.
  10. Practical lab exercises.

Traffic Capture

  1. Pre-capture considerations and best practices.
  2. Promiscuous mode configuration.
  3. Implementing capture filters.
  4. Setting automatic stop criteria.
  5. Performing remote captures.
  6. Lab exercises.

Traffic Analysis: Tools and Methodologies

  1. Developing a comprehensive analysis checklist.
  2. Leveraging features such as name resolution, color coding, marking, ignoring, commenting, and time shift adjustments.
  3. Interpreting the Expert System insights.
  4. Accessing advanced options via context menus.
  5. Interpreting data with reference patterns; assessing the impact of OS/driver Offload features.
  6. Saving and exporting results.
  7. Lab exercises and real-world case studies.


Traffic Analysis: Tools and Methodologies (Continued)

  1. Advanced filtering: Creating display filters, preparing "in-flight" filters, using macros, and following data streams.
  2. Quantitative analysis techniques.
    1. Reviewing basic descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, and IP-specific metrics.
    2. Protocol-specific deep dives (e.g., TCP Stream Graphs).
    3. Creating advanced custom statistics using I/O Graphs.
    4. Visualizing data flows.

Traffic Analysis: Protocol Deep Dives

  1. Data-Link Layer: Analysis of Ethernet II.
  2. Network Layer: Analysis of IPv4.
  3. Transport Layer: TCP and UDP behaviors.
    1. Identifying packet loss and recovery mechanisms.
    2. Detecting Previous Segment Lost and Out-of-Order Segments.
    3. Analyzing Duplicate ACKs and Fast Retransmissions.
    4. Investigating TCP Retransmissions.
    5. Diagnosing Zero Window, Window changes, and other flow control issues.
  4. Application Layer: HTTP and FTP analysis.
  5. Lab exercises and case studies.

Traffic Analysis: Diagnosing Common Performance Issues

  1. Identifying root causes of performance degradation.
  2. Analyzing packet loss.
  3. Addressing bandwidth constraints through a layered measurement approach.
  4. Assessing and visualizing end-to-end latency.
  5. Practical lab exercises.
  6. Utilizing Wireshark command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. editcap, mergecap, capinfos, and text2pcap utilities.

Advanced Topics

  1. Advanced filtering techniques and grouped I/O statistics.
  2. Course summary and Q&A session.

Requirements

1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack is required.

2. Foundational knowledge of Unix/Linux operating systems is expected, including proficiency with the UNIX terminal, directory navigation, file management (copying, moving, deleting), redirection, pipes, and process management (listing suspended and background processes).

Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All software should be updated to the latest stable release.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories