Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Overview of Network Analysis
- Foundations of the OSI reference model and TCP/IP networks.
- Overview of troubleshooting tools and methodologies.
- Introduction to Wireshark.
- Understanding Wireshark: Portable versions and available resources.
- Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- System architecture and processing flow: Identifying what Wireshark cannot observe and the reasons why.
- Supported protocols and dissectors.
- Configurations and preferences: Global settings and profile-specific adjustments.
- Understanding time values within captures.
- Practical laboratory exercises.
Traffic Capture
- Considerations prior to initiating a capture.
- Promiscuous mode.
- Implementing capture filters.
- Defining automatic stop criteria.
- Performing remote captures.
- Practical laboratory exercises.
Traffic Analysis: Tools and Approaches
- The analysis checklist.
- Leveraging features: Name resolution, colour coding, marking, ignoring, adding comments, and managing time references and shifts.
- Interpreting the Expert Information system.
- Utilising context-sensitive options via right-click functionality.
- Data interpretation: Recognising reference patterns and the impact of OS/driver Offload features.
- Exporting and saving analysis results.
- Practical exercises and case studies.
Traffic Analysis: Tools and Approaches (Continued)
- Traffic filtering: Display filters (preparing dynamic filters, macros) and following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graphs.
- Flow visualisation techniques.
Traffic Analysis: Protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP and UDP.
- Packet loss and recovery mechanisms.
- Events involving lost previous segments and Out-of-Order Segments.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, window size changes, and other window-related issues.
- Application Layer: HTTP and FTP.
- Practical exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Root causes of performance degradation.
- Diagnosing packet loss.
- Bandwidth constraints: A layered approach to measurement.
- Latency: Assessing end-to-end latency and visualisation methods.
- Practical laboratory exercises.
- Wireshark command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
- editcap, mergecap, capinfos, and text2pcap.
Advanced Topics
- Advanced filtering techniques and grouped I/O statistics.
- Summary review and Q&A session.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental understanding of Unix/Linux operating systems: UNIX terminal usage, directory structures, file and directory listing, directory creation, navigation, file manipulation (copying, moving, deleting), input/output redirection, piping, and process management (including suspended and background processes).
Hardware & Software Requirements 1. Hardware: A minimum of 16GB of RAM and at least 60GB of available disk space. 2. Operating System: Ubuntu Linux is recommended. Users of this system should ensure the following utilities are installed: ip, iperf, and ipcalc. 3. Software: The Wireshark application (available at https://www.wireshark.org/download.html).
All components should be updated to the latest stable release versions.
35 Hours
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge