Get in Touch

Course Outline

Overview of Network Analysis

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. Understanding Wireshark: Portable versions and available resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and processing flow: Identifying what cannot be observed with Wireshark and why.
  7. Supported protocols and dissectors.
  8. Preferences and configurations: Global and profile-specific settings.
  9. Interpreting time values.
  10. Lab exercises.

Capturing Traffic

  1. Pre-capture considerations.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture capabilities.
  6. Lab exercises.

Traffic Analysis: Tools and Approaches

  1. The analysis checklist.
  2. Leveraging features: Name resolution, colorization, marking, ignoring, commenting, and utilizing time references and shifts.
  3. Understanding the Expert System.
  4. Accessing options via Right-Click functionality.
  5. Interpretation: Reference patterns and the impact of OS/driver Offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic Analysis: Tools and Approaches (Continued)

  1. Filtering traffic: Display filters (preparing "in-flight" filters, macros) and following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic Analysis: Protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Previous segment lost and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Root causes of performance problems.
  2. Packet loss analysis.
  3. Bandwidth issues: A layered approach to measurement.
  4. Latency: Assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Advanced filters and grouped iostats.
  2. Summary and Q&A.

Requirements

1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental understanding of Unix/Linux operating systems: proficiency with the UNIX terminal, directory structures, file and directory management (listing, creating, changing, copying, moving, and deleting), along with concepts such as redirection, pipes, and process management (including listing suspended and background processes).

Hardware & Software Requirements
1. Hardware: Minimum 16GB of RAM and at least 60GB of free disk space.
2. Operating System: Ubuntu Linux OS is recommended. If using this environment, ensure the following applications are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All software components should be updated to the latest stable, available releases.

 35 Hours

Testimonials (3)

Related Categories