TCP/IP Network Traffic Analysis with Wireshark ( nettraffanalyswireshark | 35 hours )
1. Familiarity with ISO OSI Reference Model - ITU-T X.200 and TCP/IP protocol stack.
2. Basic knowledge of Unix/Linux OS: UNIX terminal, directory structure, listing files and directo-
ries, making directories, changing to a different directory, copying, moving and removing files and directories, redirection, pipes, processes - listing suspended and background processes.
Hardware & Software
1. HW: min 16GB of RAM, min 60GB free disk space available.
2. OS: Ubuntu Linux OS is preferred. In this case the following applications should be installed: ip,
iperf, ipcalc.
3. SW: Wireshark application (https://www.wireshark.org/download.html).
All should be in latest stable, available releases.
Wireshark is a free open source packet analyzer used for troubleshooting network issues. Network packet analysis is a technique used to view, in real time, the raw data sent and received over a network interface. This is useful for troubleshooting network configuration and network application problems.
In this instructor-led, live training (onsite or remote), participants will learn advanced techniques for troubleshooting the functionality and performance of a network and its applications. This course is an extension of "Network Troubleshooting with Wireshark", which focuses primarily on common HTTP applications. In this training, we consider protocols and connection mediums such as Wi-Fi, HTTPS, SMTP, enterprise applications and more.
By the end of this training, participants will be able to:
- Isolate and solve network security issues using the Wireshark CLI
- Troubleshoot applications that use protocols beyond HTTP, including HTTPS, FTP, mail, DNS, etc.
- Troubleshoot network connection problems in enterprise applications such as databases, RPC, etc.
- Troubleshoot connection problems in media applications such as VoIP and streaming
- Use network forensics to trace and detect security issues
Audience
- Network engineers
- Network and computer technicians
Format of the Course
- Part lecture, part discussion, exercises and heavy hands-on practice
Day 1
Network analysis overview
- OSI reference model and TCP/IP networks essentials.
- Troubleshooting tools, methodologies.
- Introduction to Wireshark
- What is Wireshark? Portable Wireshark. Resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, ... .
- Architecture and processing flow. What and why cannot be seen with Wireshark?
- Supported protocols. Dissectors.
- Preferences and configurations; global and profile specific.
- Time values.
- Lab exercises.
Day 2
Capture traffic
- Things to consider before start.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture.
- Lab exercises.
Traffic analysis: tools and approaches
- Analysis checklist.
- Using features: name resolution, colorization, marking, ignoring, commenting, using time references, time shifts, etc.
- Understanding Expert System.
- Accessing options through Right-Click functionality.
- Interpretation (reference patterns), OS/driver Offload features impact.
- Saving results.
- Lab exercises and case studies.
Day 3
Traffic analysis: tools and approaches (cont.)
- Filtering traffic: Display filters (preparing "in-flight" filters, macros), following stream.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packets Lengths, IP-specific.
- Protocol specific analysis (e.g.: TCP Stream Graphs).
- Advanced custom statistics with I/O Graph.
- Flow visualization.
Day 4
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery.
- Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes and other window problems.
- Application layer: HTTP, FTP.
- Lab exercises and case studies.
Day 5
Traffic analysis: common issues in network performance assessment
- Cause of performance problems.
- Packet loss.
- Bandwidth issues. Layered approach to measurement.
- Latency: assessing end to end latency, visualization.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based wireshark) / dumpcap / rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced topics
- Advanced filters, grouped iostats.
- Summary and Q&A.
United Arab Emirates - TCP/IP Network Traffic Analysis with Wireshark
Qatar - TCP/IP Network Traffic Analysis with Wireshark
Egypt - TCP/IP Network Traffic Analysis with Wireshark
Saudi Arabia - TCP/IP Network Traffic Analysis with Wireshark
South Africa - TCP/IP Network Traffic Analysis with Wireshark
Brasil - TCP/IP Network Traffic Analysis with Wireshark
Canada - TCP/IP Network Traffic Analysis with Wireshark
中国 - TCP/IP Network Traffic Analysis with Wireshark
香港 - TCP/IP Network Traffic Analysis with Wireshark
澳門 - TCP/IP Network Traffic Analysis with Wireshark
台灣 - TCP/IP Network Traffic Analysis with Wireshark
USA - TCP/IP Network Traffic Analysis with Wireshark
Österreich - TCP/IP Network Traffic Analysis with Wireshark
Schweiz - TCP/IP Network Traffic Analysis with Wireshark
Deutschland - TCP/IP Network Traffic Analysis with Wireshark
Czech Republic - TCP/IP Network Traffic Analysis with Wireshark
Denmark - TCP/IP Network Traffic Analysis with Wireshark
Estonia - TCP/IP Network Traffic Analysis with Wireshark
Finland - TCP/IP Network Traffic Analysis with Wireshark
Greece - TCP/IP Network Traffic Analysis with Wireshark
Magyarország - TCP/IP Network Traffic Analysis with Wireshark
Ireland - TCP/IP Network Traffic Analysis with Wireshark
Luxembourg - TCP/IP Network Traffic Analysis with Wireshark
Latvia - TCP/IP Network Traffic Analysis with Wireshark
España - TCP/IP Network Traffic Analysis with Wireshark
Italia - TCP/IP Network Traffic Analysis with Wireshark
Lithuania - TCP/IP Network Traffic Analysis with Wireshark
Nederland - TCP/IP Network Traffic Analysis with Wireshark
Norway - TCP/IP Network Traffic Analysis with Wireshark
Portugal - TCP/IP Network Traffic Analysis with Wireshark
România - TCP/IP Network Traffic Analysis with Wireshark
Sverige - TCP/IP Network Traffic Analysis with Wireshark
Türkiye - TCP/IP Network Traffic Analysis with Wireshark
Malta - TCP/IP Network Traffic Analysis with Wireshark
Belgique - TCP/IP Network Traffic Analysis with Wireshark
France - TCP/IP Network Traffic Analysis with Wireshark
日本 - TCP/IP Network Traffic Analysis with Wireshark
Australia - TCP/IP Network Traffic Analysis with Wireshark
Malaysia - TCP/IP Network Traffic Analysis with Wireshark
New Zealand - TCP/IP Network Traffic Analysis with Wireshark
Philippines - TCP/IP Network Traffic Analysis with Wireshark
Singapore - TCP/IP Network Traffic Analysis with Wireshark
Thailand - TCP/IP Network Traffic Analysis with Wireshark
Vietnam - TCP/IP Network Traffic Analysis with Wireshark
India - TCP/IP Network Traffic Analysis with Wireshark
Argentina - TCP/IP Network Traffic Analysis with Wireshark
Chile - TCP/IP Network Traffic Analysis with Wireshark
Costa Rica - TCP/IP Network Traffic Analysis with Wireshark
Ecuador - TCP/IP Network Traffic Analysis with Wireshark
Guatemala - TCP/IP Network Traffic Analysis with Wireshark
Colombia - TCP/IP Network Traffic Analysis with Wireshark
México - TCP/IP Network Traffic Analysis with Wireshark
Panama - TCP/IP Network Traffic Analysis with Wireshark
Peru - TCP/IP Network Traffic Analysis with Wireshark
Uruguay - TCP/IP Network Traffic Analysis with Wireshark
Venezuela - TCP/IP Network Traffic Analysis with Wireshark
Polska - TCP/IP Network Traffic Analysis with Wireshark
United Kingdom - TCP/IP Network Traffic Analysis with Wireshark
South Korea - TCP/IP Network Traffic Analysis with Wireshark
Pakistan - TCP/IP Network Traffic Analysis with Wireshark
Sri Lanka - TCP/IP Network Traffic Analysis with Wireshark
Bulgaria - TCP/IP Network Traffic Analysis with Wireshark
Bolivia - TCP/IP Network Traffic Analysis with Wireshark
Indonesia - TCP/IP Network Traffic Analysis with Wireshark
Kazakhstan - TCP/IP Network Traffic Analysis with Wireshark
Moldova - TCP/IP Network Traffic Analysis with Wireshark
Morocco - TCP/IP Network Traffic Analysis with Wireshark
Tunisia - TCP/IP Network Traffic Analysis with Wireshark
Kuwait - TCP/IP Network Traffic Analysis with Wireshark
Oman - TCP/IP Network Traffic Analysis with Wireshark
Slovakia - TCP/IP Network Traffic Analysis with Wireshark
Kenya - TCP/IP Network Traffic Analysis with Wireshark
Nigeria - TCP/IP Network Traffic Analysis with Wireshark
Botswana - TCP/IP Network Traffic Analysis with Wireshark
Slovenia - TCP/IP Network Traffic Analysis with Wireshark
Croatia - TCP/IP Network Traffic Analysis with Wireshark
Serbia - TCP/IP Network Traffic Analysis with Wireshark