Get in Touch

Course Outline

Overview of Network Analysis

  1. Fundamentals of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. What is Wireshark? Portable versions and relevant resources.
  5. Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
  6. Architecture and processing flow: Identifying data that cannot be observed via Wireshark and the reasons why.
  7. Supported protocols and dissectors.
  8. Configuring preferences and settings, both global and profile-specific.
  9. Understanding time values.
  10. Practical lab exercises.

Capturing Traffic

  1. Key considerations before starting a capture.
  2. Promiscuous mode.
  3. Setting up capture filters.
  4. Defining automatic stop criteria.
  5. Performing remote captures.
  6. Practical lab exercises.

Traffic Analysis: Tools and Approaches

  1. Creating an analysis checklist.
  2. Leveraging features: name resolution, colorization, marking, ignoring, commenting, and utilizing time references and shifts.
  3. Understanding the Expert System.
  4. Accessing options via right-click functionality.
  5. Interpretation (reference patterns) and the impact of OS/driver offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.

Traffic Analysis: Tools and Approaches (Continued)

  1. Filtering traffic: Display filters (preparing dynamic filters, macros) and stream following.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic Analysis: Protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Handling previous segment loss and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Identifying the root causes of performance problems.
  2. Analyzing packet loss.
  3. Bandwidth issues and the layered approach to measurement.
  4. Latency: assessing end-to-end latency and visualization techniques.
  5. Practical lab exercises.
  6. Command-line tools (Wireshark ecosystem):
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Advanced filters and grouped I/O statistics.
  2. Summary and Q&A session.

Requirements

1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental proficiency in Unix/Linux operating systems: using the UNIX terminal, navigating directory structures, listing, creating, modifying, and managing files and directories, along with redirection, pipes, and process management (including listing suspended and background processes).

Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and 60GB of available free disk space.
2. Operating System: Ubuntu Linux is recommended. Users should have the following utilities installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All software must be at the latest stable, available release.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories