Introduction to Network Analysis
Introduction to Network Analysis
Introduction to Wireshark
Collecting the Data
Configuring and Using Wireshark
Configuring Wireshark
Building and optimizing configuration Profiles for data capture
Using capture filters to capture specific suspect traffic
Location – How Network Infrastructure Devices Effect Ethernet Network Analysis
Hubs, Switches, Bridges, Routers, Firewalls, and CSU / DSU
Constructing, Using, and Interpreting Color Rues
Define Time Values and Interpret Summaries
Answering the key questions – Interpret Basic Trace File Statistics
Creating and Applying Display Filters
Annotate, Save, Export and Print Packets
Follow Streams and Reassemble Data
Use Wireshark’s Expert System
* WCA Quiz #1
Analyzing the Data – The Protocols
Ethernet Fundamentals
Structure, Analysis, and Filtering
Analyze and identify key characteristics of v2 ethernet frames
Domain Name System (DNS)
Structure, Analysis, and Filtering
Analyze Normal DNS Queries/Responses
Address Resolution Protocol (ARP)
Structure, Analysis, and Filtering
Analyze Normal ARP Requests/Responses
Analyze Gratuitous ARP
Dynamic Host Configuration Protocol (DHCPv4) and Automatic Private IP Addressing (APIPA)
Structure, Analysis, and Filtering
Analyze Normal DHCP Traffic
Internet Protocol (IPv4/6)
Structure, Analysis, and Filtering
Analyze Normal IPv4 Traffic
Identify various the various IP addresses, classes, prefix codes
Internet Control Message Protocol (ICMPv4/6)
Structure, Analysis, and Filtering
Type & Code Numbers
* WCA Quiz #2
User Datagram (UDP)
Structure, Analysis, and Filtering
Analyze Normal UDP Traffic
Transmission Control Protocol (TCP)
Structure, Analysis, and Filtering
TCP-IP Analysis Overview
Graph IO Rates & TCP Trends
Define the Establishment of TCP Connections
Define How TCP-based Services are Refused
Define How TCP Connections are Terminated
Track TCP Packet Sequencing
Define How TCP Recovers from Packet Loss
Improve Packet Loss Recovery with Selective Acknowledgments
Define TCP Flow Control
Detect and Analyze TCP Performance Problems
Recap – Effective Troubleshooting Techniques
Determine network topology only using information in a packet capture
Perform TCP sequence and acknowledgment number analysis
Distinguish server performance from slow transfer times (HTTP)
Identify the effect of high RTT on request/response protocols
Identify the effect of a low window size in combination with high RTT
Identify potential network communication issues using ARP, DHCPv4, and ICMPv4/6 information
* WCA Quiz #3 & Practice Test