Course Outline
Overview of Network Analysis
- Fundamentals of the OSI reference model and TCP/IP networking.
- Essential troubleshooting tools and methodologies.
- Introduction to the Wireshark platform.
- Understanding Wireshark: Portable versions and available resources.
- Anatomy of the Wireshark GUI: Packet List, Details, Packet Bytes panes, and the Status Bar.
- Internal architecture and data processing flow; limitations of what Wireshark can visualize.
- Overview of supported protocols and dissectors.
- Managing preferences and configurations, including global and profile-specific settings.
- Interpreting time values within captures.
- Practical lab exercises.
Traffic Capture
- Pre-capture considerations and best practices.
- Utilizing Promiscuous mode.
- Applying capture filters for targeted data collection.
- Defining automatic stop criteria.
- Performing remote captures.
- Hands-on lab exercises.
Traffic Analysis: Tools and Methodologies
- Establishing a comprehensive analysis checklist.
- Leveraging analytical features: name resolution, color coding, packet marking, ignoring, commenting, and time shift utilities.
- Mastering the Expert Information system.
- Utilizing context-sensitive options via Right-Click menus.
- Interpreting data patterns and understanding the impact of OS/driver Offload features.
- Exporting and saving analysis results.
- Case studies and practical lab exercises.
Traffic Analysis: Advanced Tools and Approaches
- Refining traffic views: Creating and preparing Display filters (including "in-flight" filters and macros) and following streams.
- Conducting quantitative analysis.
- Reviewing predefined statistics: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, and packet length distributions.
- Protocol-specific deep dives (e.g., TCP Stream Graphs).
- Generating advanced custom statistics using I/O Graphs.
- Visualizing network flows.
Traffic Analysis: Protocol Deep Dives
- Data-Link Layer: Analysis of Ethernet II frames.
- Network Layer: Inspection of IPv4 packets.
- Transport Layer: In-depth look at TCP and UDP.
- Diagnosing packet loss and recovery mechanisms.
- Identifying Previous Segment Lost and Out-of-Order Segments events.
- Understanding Duplicate ACKs and Fast Retransmissions.
- Analyzing TCP Retransmissions.
- Resolving Zero Window, Window size changes, and related flow control issues.
- Application Layer: Examination of HTTP and FTP traffic.
- Applied lab exercises and case studies.
Addressing Common Network Performance Issues
- Identifying root causes of performance degradation.
- Analyzing packet loss patterns.
- Assessing bandwidth constraints using a layered measurement approach.
- Evaluating end-to-end latency and visualizing delay impacts.
- Practical lab exercises.
- Leveraging (Wireshark) command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
- Packet manipulation tools: editcap, mergecap, capinfos, and text2pcap.
Advanced Topics
- Constructing advanced filters and analyzing grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Proficiency with Unix/Linux operating systems, including UNIX terminal commands, directory navigation, file management (copying, moving, deleting), process management (listing suspended/background tasks), and the use of redirection and pipes.
Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (available at https://www.wireshark.org/download.html).
All software components should be updated to the latest stable releases.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge