Get in Touch

Course Outline

Network analysis overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. What is Wireshark? Portable Wireshark options. Available resources.
  5. Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and data processing flow. Identifying what Wireshark cannot see and why.
  7. Supported protocols and dissectors.
  8. Preferences and configurations: global settings and profile-specific options.
  9. Understanding time values.
  10. Lab exercises.

Capturing traffic

  1. Considerations before initiating a capture.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture techniques.
  6. Lab exercises.

Traffic analysis: tools and approaches

  1. Creating an analysis checklist.
  2. Leveraging features: name resolution, colorization, marking, ignoring, commenting, and using time references or shifts.
  3. Understanding the Expert System.
  4. Accessing options via right-click functionality.
  5. Interpretation using reference patterns and the impact of OS/driver Offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic analysis: tools and approaches (continued)

  1. Filtering traffic: Display filters (preparing "in-flight" filters, macros) and following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graphs.
    4. Flow visualization.

Traffic analysis: protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Handling Previous Segment Lost and Out-of-Order Segments events.
    3. Managing Duplicate ACKs and Fast Retransmissions.
    4. Analyzing TCP Retransmissions.
    5. Addressing Zero Window, window changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic analysis: common issues in network performance assessment

  1. Identifying the root causes of performance problems.
  2. Diagnosing packet loss.
  3. Bandwidth issues and a layered approach to measurement.
  4. Latency: Assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced topics

  1. Advanced filters and grouped iostats.
  2. Course summary and Q&A session.

Requirements

1. A solid understanding of the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Foundational knowledge of Unix/Linux operating systems, including the UNIX terminal, directory structure, file and directory management (listing, creating, navigating, copying, moving, and deleting), as well as redirection, pipes, and process management (listing suspended and background processes).

Hardware & Software
1. HW: Minimum 16GB of RAM and 60GB of available disk space.
2. OS: Ubuntu Linux OS is recommended. Ensure the following applications are installed: ip,
iperf, and ipcalc.
3. SW: The Wireshark application (https://www.wireshark.org/download.html).

All tools and software should be updated to the latest stable releases.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories