Get in Touch

Course Outline

Network Analysis Fundamentals

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Overview of troubleshooting tools and methodologies.
  3. Introduction to the Wireshark platform
  4. What is Wireshark? Portable versions and available resources.
  5. Understanding the Wireshark GUI: Packet List, Details, Packet Bytes panes, and the Status Bar.
  6. Architecture and data processing flow; limitations and invisible elements.
  7. Supported protocols and the role of dissectors.
  8. Configuration management: global settings versus profile-specific preferences.
  9. Interpretation of time values.
  10. Practical lab exercises.

Capturing Network Traffic

  1. Key considerations before initiating a capture.
  2. Utilizing promiscuous mode.
  3. Applying capture filters.
  4. Setting automatic stop criteria.
  5. Configuring remote captures.
  6. Practical lab exercises.

Traffic Analysis: Tools and Methodologies

  1. Establishing a comprehensive analysis checklist.
  2. Leveraging built-in features: name resolution, color-coding, packet marking, ignoring, commenting, and time-shift references.
  3. Deciphering the Expert System output.
  4. Accessing contextual options via right-click functionality.
  5. Interpreting data through reference patterns and understanding the impact of OS/driver offload features.
  6. Saving and exporting analysis results.
  7. Lab exercises and real-world case studies.


Traffic Analysis: Tools and Methodologies (Continued)

  1. Filtering traffic: Crafting display filters (including "in-flight" filters and macros) and following streams.
  2. Quantitative analysis.
    1. Reviewing predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Performing protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Generating advanced custom statistics using I/O Graphs.
    4. Visualizing data flows.

Traffic Analysis: Protocol Deep Dive

  1. Data-Link Layer: Examining Ethernet II.
  2. Network Layer: Analyzing IPv4.
  3. Transport Layer: Investigating TCP and UDP.
    1. Diagnosing packet loss and recovery mechanisms.
    2. Identifying "Previous segment lost" and "Out-of-Order Segments" events.
    3. Analyzing Duplicate ACKs and Fast Retransmissions.
    4. Evaluating TCP Retransmissions.
    5. Addressing Zero Window, window scaling changes, and other window-related issues.
  4. Application Layer: Reviewing HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Network Performance Issues

  1. Identifying root causes of performance degradation.
  2. Analyzing packet loss patterns.
  3. Investigating bandwidth constraints using a layered measurement approach.
  4. Assessing and visualizing end-to-end latency.
  5. Practical lab exercises.
  6. Exploring (Wireshark) command-line utilities:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Utilizing advanced filters and grouped I/O statistics.
  2. Course summary and Q&A session.

Requirements

1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental proficiency with Unix/Linux operating systems, including UNIX terminal usage, directory navigation, file management (creating, copying, moving, and deleting), and process control (managing suspended and background tasks).



Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of available disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All software components must be updated to the latest stable releases.
 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories