Features, functions and basic operation of Ethereal/Wireshark Analyser
- Introduction and operation of Wireshark
- Live Capture and Live Capture settings
- Display options and basic interpretation
- Working with Display Filters and Capture Filters
- File Input and Output
Advanced features of Wireshark Analyser
- Preferences and user profiles
- Name resolution
- Packet Reassembly
- Expert Information
- Packet colorisation
Methodology and techniques of network analysis and troubleshooting
- What is packet analysis?
- Steps and techniques for analysing traffic
- Analysing Switched Ethernet – Tapping into the network
- Capturing wireless network traffic
- Measuring network delay and response time
- Measuring network throughput and overhead
Statistics and Baselining
- Terms and Overview
- Wireshark Statistics
- Application Profiles
Analysing networks and applications
- Fault isolation
- Typical network related problems
- Application types and typical application related problems
Switched Ethernet analysis
- Duplex & Speed Issues
- Spanning Tree operation and Spanning Tree analysis
- Analyzing VLANs, VLAN-Tagging
TCP/IP analysis of the network layer
- IP addressing
- Typical IP scenarios
- IP options
- ICMP, ARP and DHCP
TCP/IP analysis of the transport layer
- TCP functions
- Session Setup, Data Transfer and Session Teardown
- Window Mechanism and Window optimization
- TCP options (SACK, Window Scaling) and TCP timers
- UDP functions
Analysing and troubleshooting TCP/IP with Wireshark
- Wireshark preferences for advanced TCP/IP analysis
- Typical TCP/IP related problems
- Wireshark Expert Info messages and their meanings
TCP/IP applications