Course Outline
Overview of Network Analysis
- Fundamentals of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark.
- What is Wireshark? Portable versions and relevant resources.
- Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
- Architecture and processing flow: Identifying data that cannot be observed via Wireshark and the reasons why.
- Supported protocols and dissectors.
- Configuring preferences and settings, both global and profile-specific.
- Understanding time values.
- Practical lab exercises.
Capturing Traffic
- Key considerations before starting a capture.
- Promiscuous mode.
- Setting up capture filters.
- Defining automatic stop criteria.
- Performing remote captures.
- Practical lab exercises.
Traffic Analysis: Tools and Approaches
- Creating an analysis checklist.
- Leveraging features: name resolution, colorization, marking, ignoring, commenting, and utilizing time references and shifts.
- Understanding the Expert System.
- Accessing options via right-click functionality.
- Interpretation (reference patterns) and the impact of OS/driver offload features.
- Saving analysis results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Approaches (Continued)
- Filtering traffic: Display filters (preparing dynamic filters, macros) and stream following.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graph.
- Flow visualization.
Traffic Analysis: Protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery mechanisms.
- Handling previous segment loss and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, window changes, and other window-related issues.
- Application Layer: HTTP and FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Identifying the root causes of performance problems.
- Analyzing packet loss.
- Bandwidth issues and the layered approach to measurement.
- Latency: assessing end-to-end latency and visualization techniques.
- Practical lab exercises.
- Command-line tools (Wireshark ecosystem):
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap.
Advanced Topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A session.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental proficiency in Unix/Linux operating systems: using the UNIX terminal, navigating directory structures, listing, creating, modifying, and managing files and directories, along with redirection, pipes, and process management (including listing suspended and background processes).
Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and 60GB of available free disk space.
2. Operating System: Ubuntu Linux is recommended. Users should have the following utilities installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All software must be at the latest stable, available release.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge