Get in Touch

Course Outline

Network Analysis Overview

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark
  4. What is Wireshark? Portable versions and available resources.
  5. Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and processing flow, including limitations on visibility.
  7. Supported protocols and dissectors.
  8. Preferences and configurations, both global and profile-specific.
  9. Understanding time values.
  10. Lab exercises.

Capturing Traffic

  1. Preliminary considerations before starting a capture.
  2. Promiscuous mode.
  3. Capture filters.
  4. Automatic stop criteria.
  5. Remote capture techniques.
  6. Lab exercises.

Traffic Analysis: Tools and Approaches

  1. Analytical checklists.
  2. Leveraging features such as name resolution, colorization, marking, ignoring, commenting, and time references.
  3. Understanding the Expert System.
  4. Accessing options via right-click functionality.
  5. Interpretation patterns and the impact of OS/driver offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic Analysis: Tools and Approaches (Continued)

  1. Filtering traffic: Display filters (including in-flight filters and macros) and stream following.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic Analysis: Protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Previous segment lost and Out-of-Order Segments events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Root causes of performance problems.
  2. Packet loss analysis.
  3. Bandwidth issues and a layered approach to measurement.
  4. Latency: assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. Wireshark command-line tools:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Advanced filters and grouped I/O statistics.
  2. Summary and Q&A session.

Requirements

1. Familiarity with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Basic proficiency in Unix/Linux operating systems: navigating the UNIX terminal, understanding directory structures, listing files and directories, creating and changing directories, copying, moving, and deleting files and directories, as well as utilizing redirection, pipes, and managing suspended and background processes.

Hardware & Software Requirements:
1. HW: Minimum 16GB of RAM and at least 60GB of free disk space.
2. OS: Ubuntu Linux is recommended. Ensure the following applications are installed: ip, iperf, and ipcalc.
3. SW: The Wireshark application (https://www.wireshark.org/download.html).

All software should be up to date with the latest stable releases.

 35 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories