Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Network Analysis Overview
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting tools and methodologies.
- Introduction to Wireshark.
- What is Wireshark? Portable versions and available resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- Architecture and data processing flow; limitations on visibility with Wireshark.
- Supported protocols and dissectors.
- Preferences and configuration settings; global versus profile-specific settings.
- Interpretation of time values.
- Practical lab exercises.
Capturing Traffic
- Key considerations prior to starting a capture.
- Promiscuous mode.
- Capture filters.
- Automatic stop conditions.
- Remote capture techniques.
- Lab exercises.
Traffic Analysis: Tools and Approaches
- Analytical checklists.
- Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System.
- Accessing options via Right-Click functionality.
- Interpretation using reference patterns; impact of OS/driver Offload features.
- Saving analysis results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Approaches (Continued)
- Filtering traffic: Display filters (preparing "in-flight" filters, macros), and following streams.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics using I/O Graphs.
- Flow visualization techniques.
Traffic Analysis: Protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery mechanisms.
- Events such as Previous segment lost and Out-of-Order Segments.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, window changes, and other window-related issues.
- Application Layer: HTTP, FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Issues in Network Performance Assessment
- Root causes of performance degradation.
- Packet loss analysis.
- Bandwidth issues and a layered approach to measurement.
- Latency: assessing end-to-end latency and visualization techniques.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap
Advanced Topics
- Advanced filtering techniques and grouped I/O statistics.
- Summary and Q&A session.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental understanding of Unix/Linux operating systems, including: UNIX terminal usage, directory structure, file and directory listing, directory creation, navigating directories, copying, moving, and deleting files/directories, redirection, pipes, and managing processes (including suspended and background processes).
Hardware & Software Requirements: 1. Hardware: Minimum 16GB of RAM and 60GB of free disk space. 2. Operating System: Ubuntu Linux is recommended. Ensure the following applications are installed: ip, iperf, and ipcalc. 3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All components should be running the latest stable releases available.
35 Hours
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge