Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Network Analysis Overview
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark
- Understanding Wireshark: Portable versions and resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
- Architecture and processing flow. Limitations of Wireshark visibility.
- Supported protocols and dissectors.
- Preferences and configurations: global and profile-specific settings.
- Understanding time values.
- Lab exercises.
Capturing Traffic
- Key considerations before starting a capture.
- Promiscuous mode explained.
- Capture filters.
- Automatic stop criteria.
- Remote capture techniques.
- Lab exercises.
Traffic Analysis: Tools and Approaches
- Analysis checklist.
- Leveraging features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Navigating options via Right-Click functionality.
- Interpretation (reference patterns) and understanding OS/driver Offload features impact.
- Saving analysis results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Approaches (Continued)
- Traffic filtering: Display filters (creating "in-flight" filters, macros) and following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graphs.
- Flow visualization techniques.
Traffic Analysis: Protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery mechanisms.
- Events involving lost previous segments and out-of-order segments.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes, and other window-related issues.
- Application Layer: HTTP, FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Causes of performance problems.
- Packet loss analysis.
- Bandwidth issues: A layered approach to measurement.
- Latency: Assessing end-to-end latency and visualization.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced Topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A session.
Requirements
1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Basic proficiency with Unix/Linux OS, including: UNIX terminal usage, directory structures, file listing and management, creating, changing, copying, moving, and removing files/directories, redirection, pipes, and process management (listing suspended and background processes).
Hardware & Software Requirements: 1. Hardware: Minimum 16GB RAM and 60GB of free disk space. 2. Operating System: Ubuntu Linux is preferred. Required applications include ip, iperf, and ipcalc. 3. Software: Wireshark application (https://www.wireshark.org/download.html). All tools should be the latest stable releases.
35 Hours
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge