Course Outline
Overview of Network Analysis
- Essentials of the OSI reference model and TCP/IP networks.
- Standard troubleshooting tools and methodological approaches.
- Introduction to Wireshark.
- Understanding Wireshark: Portable version and key resources.
- Wireshark interface layout: Packet List, Details, Packet Bytes panes, and the Status Bar.
- Internal architecture and data processing flow; limitations of visibility in Wireshark.
- Supported protocols and dissectors.
- Managing preferences and configurations, both global and profile-specific.
- Understanding time values in captures.
- Practical lab exercises.
Traffic Capture
- Pre-capture considerations and best practices.
- Promiscuous mode configuration.
- Implementing capture filters.
- Setting automatic stop criteria.
- Performing remote captures.
- Lab exercises.
Traffic Analysis: Tools and Methodologies
- Developing a comprehensive analysis checklist.
- Leveraging features such as name resolution, color coding, marking, ignoring, commenting, and time shift adjustments.
- Interpreting the Expert System insights.
- Accessing advanced options via context menus.
- Interpreting data with reference patterns; assessing the impact of OS/driver Offload features.
- Saving and exporting results.
- Lab exercises and real-world case studies.
Traffic Analysis: Tools and Methodologies (Continued)
- Advanced filtering: Creating display filters, preparing "in-flight" filters, using macros, and following data streams.
- Quantitative analysis techniques.
- Reviewing basic descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, and IP-specific metrics.
- Protocol-specific deep dives (e.g., TCP Stream Graphs).
- Creating advanced custom statistics using I/O Graphs.
- Visualizing data flows.
Traffic Analysis: Protocol Deep Dives
- Data-Link Layer: Analysis of Ethernet II.
- Network Layer: Analysis of IPv4.
- Transport Layer: TCP and UDP behaviors.
- Identifying packet loss and recovery mechanisms.
- Detecting Previous Segment Lost and Out-of-Order Segments.
- Analyzing Duplicate ACKs and Fast Retransmissions.
- Investigating TCP Retransmissions.
- Diagnosing Zero Window, Window changes, and other flow control issues.
- Application Layer: HTTP and FTP analysis.
- Lab exercises and case studies.
Traffic Analysis: Diagnosing Common Performance Issues
- Identifying root causes of performance degradation.
- Analyzing packet loss.
- Addressing bandwidth constraints through a layered measurement approach.
- Assessing and visualizing end-to-end latency.
- Practical lab exercises.
- Utilizing Wireshark command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
- editcap, mergecap, capinfos, and text2pcap utilities.
Advanced Topics
- Advanced filtering techniques and grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack is required.
2. Foundational knowledge of Unix/Linux operating systems is expected, including proficiency with the UNIX terminal, directory navigation, file management (copying, moving, deleting), redirection, pipes, and process management (listing suspended and background processes).
Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All software should be updated to the latest stable release.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge