Get in Touch

Course Outline

Network analysis overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. Understanding Wireshark: Portable version and resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, etc.
  6. Architecture and processing flow. Limitations: What cannot be seen with Wireshark?
  7. Supported protocols and dissectors.
  8. Preferences and configurations: Global and profile-specific settings.
  9. Time value handling.
  10. Lab exercises.

Capture traffic

  1. Key considerations before starting.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture capabilities.
  6. Lab exercises.

Traffic analysis: tools and approaches

  1. Analysis checklist.
  2. Utilizing features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
  3. Understanding the Expert System.
  4. Navigating options via Right-Click functionality.
  5. Interpretation using reference patterns and impact of OS/driver Offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic analysis: tools and approaches (cont.)

  1. Traffic filtering: Display filters (creating 'in-flight' filters, macros), following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic analysis: protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP, UDP.
    1. Packet loss and recovery mechanisms.
    2. Handling previous segment loss and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, Window changes, and other window-related issues.
  4. Application Layer: HTTP, FTP.
  5. Lab exercises and case studies.

Traffic analysis: common issues in network performance assessment

  1. Causes of performance problems.
  2. Packet loss analysis.
  3. Bandwidth issues: Layered approach to measurement.
  4. Latency: Assessing and visualizing end-to-end latency.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, tcpdump.
    2. editcap, mergecap, capinfos, text2pcap.

Advanced topics

  1. Advanced filters and grouped iostats.
  2. Summary and Q&A.

Requirements

1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Basic knowledge of Unix/Linux OS: UNIX terminal usage, directory structure navigation, file operations (listing, creating, moving, copying, deleting), redirection, pipes, and process management (listing suspended and background processes).

Hardware & Software Requirements
1. Hardware: Minimum 16GB RAM and at least 60GB of free disk space.
2. OS: Ubuntu Linux is preferred. The following applications must be installed: ip, iperf, ipcalc.
3. Software: Wireshark application (https://www.wireshark.org/download.html).

All components should be the latest stable available releases.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories