Get in Touch

Course Outline

Network analysis overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark
  4. What is Wireshark? Portable Wireshark. Resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, ... .
  6. Architecture and processing flow. What cannot be seen with Wireshark and why?
  7. Supported protocols. Dissectors.
  8. Preferences and configurations; global and profile specific.
  9. Time values.
  10. Lab exercises.

Capture traffic

  1. Considerations before starting.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture.
  6. Lab exercises.

Traffic analysis: tools and approaches

  1. Analysis checklist.
  2. Using features: name resolution, colorization, marking, ignoring, commenting, using time references, time shifts, etc.
  3. Understanding Expert System.
  4. Accessing options through Right-Click functionality.
  5. Interpretation (reference patterns), impact of OS/driver Offload features.
  6. Saving results.
  7. Lab exercises and case studies.


Traffic analysis: tools and approaches (cont.)

  1. Filtering traffic: Display filters (preparing "in-flight" filters, macros), following stream.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packets Lengths, IP-specific.
    2. Protocol specific analysis (e.g.: TCP Stream Graphs).
    3. Advanced custom statistics with I/O Graph.
    4. Flow visualization.

Traffic analysis: protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP, UDP.
    1. Packet loss and recovery.
    2. Previous segment lost and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, Window changes and other window problems.
  4. Application layer: HTTP, FTP.
  5. Lab exercises and case studies.

Traffic analysis: common issues in network performance assessment

  1. Cause of performance problems.
  2. Packet loss.
  3. Bandwidth issues. Layered approach to measurement.
  4. Latency: assessing end-to-end latency, visualization.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based wireshark) / dumpcap / rawshark, tcpdump
    2. editcap, mergecap, capinfos, text2pcap.

Advanced topics

  1. Advanced filters, grouped iostats.
  2. Summary and Q&A.

Requirements

1. Familiarity with the ISO OSI Reference Model - ITU-T X.200 and the TCP/IP protocol stack.

2. Basic knowledge of Unix/Linux OS: UNIX terminal, directory structure, listing files and directories, creating directories, navigating between directories, copying, moving, and removing files and directories, redirection, pipes, processes - listing suspended and background processes.

Hardware & Software
1. Hardware: Minimum 16GB of RAM, minimum 60GB of free disk space available.
2. OS: Ubuntu Linux OS is preferred. In this case, the following applications must be installed: ip,
iperf, ipcalc.
3. SW: Wireshark application (https://www.wireshark.org/download.html).

All components should be the latest stable releases available.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories