Course Outline
Overview of Network Analysis
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark
- Understanding Wireshark: Portable version and resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
- Architecture and processing flow. Limitations of what can and cannot be seen with Wireshark.
- Supported protocols and dissectors.
- Preferences and configurations: global vs. profile-specific settings.
- Time values.
- Lab exercises.
Capturing Traffic
- Key considerations before starting a capture.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture capabilities.
- Lab exercises.
Traffic Analysis: Tools and Approaches
- Analysis checklist.
- Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Navigating options via Right-Click functionality.
- Interpretation (reference patterns) and understanding the impact of OS/driver Offload features.
- Saving results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Approaches (continued)
- Filtering traffic: Display filters (creating "in-flight" filters, macros), following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graphs.
- Flow visualization.
Traffic Analysis: Protocols
\r- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery mechanisms.
- Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes, and other window-related issues.
- Application Layer: HTTP, FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Causes of performance problems.
- Packet loss analysis.
- Bandwidth issues: Layered approach to measurement.
- Latency: Assessing end-to-end latency and visualization.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced Topics
- Advanced filters and grouped I/O statistics.
- Summary and Q&A session.
Requirements
1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Basic knowledge of Unix/Linux OS: UNIX terminal, directory structure, listing files and directories, creating directories, navigating directories, copying, moving and removing files and directories, redirection, pipes, processes - listing suspended and background processes.
Hardware & Software Requirements
1. Hardware: Minimum 16GB RAM and at least 60GB of free disk space.
2. OS: Ubuntu Linux is preferred. The following applications must be installed: ip,
iperf, ipcalc.
3. SW: Wireshark application (https://www.wireshark.org/download.html).
All components should be the latest stable releases.
Testimonials (1)
Learning about the tool
Arni Josue Quiroz Vivero - Grupo Salinas
Course - Network Troubleshooting with Wireshark
Machine Translated