Wireshark for Troubleshooting Foundations
Module 1:
Troubleshooting Mindset and Methodology
- Defining a network problem
- Symptoms vs root cause
- Common troubleshooting workflows
Module 2:
Wireshark Basics Refresher
- Installing and configuring
Wireshark
- Capture interfaces and permissions
- Navigating packet list, details,
and bytes panes
Module 3:
Capture Strategies for Troubleshooting
- Capture points and placement
- Avoiding incomplete or biased
captures
- Capturing from multiple locations
Module 4:
Basic Filtering and Navigation
- Display vs capture filters
- Isolating conversations by IP, MAC,
or port
- Highlighting problem flows with
coloring rules
Protocol-Level Troubleshooting
Module 5:
Ethernet and ARP Issues
- Detecting MAC conflicts
- Identifying ARP storms or spoofing
- Troubleshooting broadcast issues
Module 6:
IP-Level Troubleshooting
- TTL, MTU, and fragmentation issues
- Identifying routing loops and black
holes
Module 7:
ICMP in Troubleshooting
- Using ping and traceroute captures
- Diagnosing unreachable hosts and
time exceeded errors
Module 8:
TCP Troubleshooting
- Understanding handshake failures
- Packet loss, retransmissions, and
out-of-order packets
- Diagnosing slow application
responses
Module 9:
UDP Troubleshooting
- Missing packets and jitter
- DNS, DHCP, and VoIP-specific issues
Advanced Analysis and Real-World Scenarios
Module 10:
Advanced Filtering and Analysis Tools
- Complex display filters
- Expert Info, Statistics, and I/O
Graphs
- Flow Graphs and Protocol Hierarchy
Module 11:
Performance and Latency Analysis
- Round-trip time measurements
- TCP window size and flow control
- Identifying application vs network
delays
Module 12:
Detecting Anomalies and Security Indicators
- Spotting suspicious traffic
patterns
- Recognizing scanning and flooding
attempts
- Overview of encrypted traffic
behavior
Module 13:
Case Studies and Final Project
- Analyzing multi-protocol captures
- Identifying root cause in complex
issues
- Documenting and presenting findings
Review and
Q&A