Get in Touch
 Duration 35 hours

Course Outline

Overview of Network Analysis

  1. Fundamentals of the OSI reference model and TCP/IP networks.
  2. Essential troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. Understanding Wireshark: Portable versions and available resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and processing flow; limitations and visibility constraints.
  7. Supported protocols and dissectors.
  8. Preferences and configurations, including global and profile-specific settings.
  9. Time values and their interpretation.
  10. Practical lab exercises.

Capturing Traffic

  1. Key considerations before initiating a capture.
  2. Promiscuous mode operation.
  3. Implementing capture filters.
  4. Setting automatic stop criteria.
  5. Performing remote captures.
  6. Practical lab exercises.

Traffic Analysis: Tools and Methodologies

  1. Establishing an analysis checklist.
  2. Leveraging features such as name resolution, colorization, marking, ignoring, commenting, and time reference management.
  3. Understanding the Expert System.
  4. Accessing options via Right-Click functionality.
  5. Interpretation strategies (reference patterns) and the impact of OS/driver Offload features.
  6. Saving and managing results.
  7. Lab exercises and case studies.

Traffic Analysis: Tools and Methodologies (Continued)

  1. Traffic filtering: Display filters (preparing "in-flight" filters, macros) and stream following.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graphs.
    4. Flow visualization techniques.

Traffic Analysis: Protocol Deep Dives

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Events involving previous segment loss and Out-of-Order Segments.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, Window changes, and other window management issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Root causes of performance degradation.
  2. Diagnosing packet loss.
  3. Bandwidth issues and the layered approach to measurement.
  4. Latency: assessing end-to-end latency and visualization methods.
  5. Practical lab exercises.
  6. (Wireshark) command-line toolkits:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Advanced filtering techniques and grouped I/O statistics.
  2. Summary and Q&A session.

Requirements

1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Foundational knowledge of Unix/Linux operating systems, including: UNIX terminal usage, directory structures, file and directory management (listing, creation, navigation, copying, moving, and deletion), as well as core concepts such as redirection, pipes, and process management (including suspended and background processes).



Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of available free disk space.
2. Operating System: Ubuntu Linux is recommended. If used, the following applications must be installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All software components should be updated to the latest stable releases available.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories