Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Network Analysis Fundamentals
- Essentials of the OSI reference model and TCP/IP networks.
- Overview of troubleshooting tools and methodologies.
- Introduction to the Wireshark platform
- What is Wireshark? Portable versions and available resources.
- Understanding the Wireshark GUI: Packet List, Details, Packet Bytes panes, and the Status Bar.
- Architecture and data processing flow; limitations and invisible elements.
- Supported protocols and the role of dissectors.
- Configuration management: global settings versus profile-specific preferences.
- Interpretation of time values.
- Practical lab exercises.
Capturing Network Traffic
- Key considerations before initiating a capture.
- Utilizing promiscuous mode.
- Applying capture filters.
- Setting automatic stop criteria.
- Configuring remote captures.
- Practical lab exercises.
Traffic Analysis: Tools and Methodologies
- Establishing a comprehensive analysis checklist.
- Leveraging built-in features: name resolution, color-coding, packet marking, ignoring, commenting, and time-shift references.
- Deciphering the Expert System output.
- Accessing contextual options via right-click functionality.
- Interpreting data through reference patterns and understanding the impact of OS/driver offload features.
- Saving and exporting analysis results.
- Lab exercises and real-world case studies.
Traffic Analysis: Tools and Methodologies (Continued)
- Filtering traffic: Crafting display filters (including "in-flight" filters and macros) and following streams.
- Quantitative analysis.
- Reviewing predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Performing protocol-specific analysis (e.g., TCP Stream Graphs).
- Generating advanced custom statistics using I/O Graphs.
- Visualizing data flows.
Traffic Analysis: Protocol Deep Dive
- Data-Link Layer: Examining Ethernet II.
- Network Layer: Analyzing IPv4.
- Transport Layer: Investigating TCP and UDP.
- Diagnosing packet loss and recovery mechanisms.
- Identifying "Previous segment lost" and "Out-of-Order Segments" events.
- Analyzing Duplicate ACKs and Fast Retransmissions.
- Evaluating TCP Retransmissions.
- Addressing Zero Window, window scaling changes, and other window-related issues.
- Application Layer: Reviewing HTTP and FTP.
- Lab exercises and case studies.
Traffic Analysis: Common Network Performance Issues
- Identifying root causes of performance degradation.
- Analyzing packet loss patterns.
- Investigating bandwidth constraints using a layered measurement approach.
- Assessing and visualizing end-to-end latency.
- Practical lab exercises.
- Exploring (Wireshark) command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
- editcap, mergecap, capinfos, and text2pcap.
Advanced Topics
- Utilizing advanced filters and grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental proficiency with Unix/Linux operating systems, including UNIX terminal usage, directory navigation, file management (creating, copying, moving, and deleting), and process control (managing suspended and background tasks).
Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of available disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All software components must be updated to the latest stable releases.
35 Hours
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge