TCP/IP Fundamentals and Wireshark Basics
Module 1:
Introduction to TCP/IP Networking
- OSI vs TCP/IP models
- Ethernet, IP, TCP, and UDP basics
- Understanding encapsulation and
packet flow
Module 2:
Wireshark Overview
- Installing Wireshark on different
platforms
- Interface tour and layout
explanation
- Capturing live network traffic
Module 3:
Basic Packet Capture and Navigation
- Choosing capture interfaces
- Starting, stopping, and saving
captures
- Navigating through packet list,
details, and bytes panes
Module 4:
Basic Filtering and Search
- Display filters vs capture filters
- Applying simple display filters
- Commonly used filters for TCP/IP
analysis
Detailed Protocol Analysis
Module 5:
Ethernet and ARP Analysis
- Ethernet frame structure
- ARP requests and replies
- Detecting ARP-related issues
Module 6: IP
Protocol Analysis
- IPv4 header fields and
fragmentation
- IPv6 basics and extension headers
- TTL, MTU, and IP options
Module 7:
ICMP Protocol Analysis
- ICMP types and codes
- Ping and traceroute analysis
- Detecting unreachable errors and
time exceeded messages
Module 8:
UDP Protocol Analysis
- UDP header fields
- DNS, DHCP, and other UDP-based
protocols
- Troubleshooting UDP communication
issues
TCP
Analysis and Troubleshooting
Module 9:
TCP Protocol Fundamentals
- TCP header fields
- Three-way handshake and connection
teardown
- TCP flags and their significance
Module 10:
TCP Performance Analysis
- Window size, scaling, and flow
control
- TCP retransmissions, duplicates,
and out-of-order packets
- Analyzing round-trip time and
throughput
Module 11:
Troubleshooting TCP Issues
- Connection resets and timeouts
- Detecting packet loss and latency
- Identifying slow application
response vs network delays
Module 12:
Wireshark Advanced Tools
- Expert Info window
- Statistics and I/O graphs
- Protocol hierarchy and flow graphs
Practical
Session
Advanced Wireshark Usage and Real-World Scenarios
Module 13:
Advanced Filtering Techniques
- Complex display filters
- Combining multiple filter
conditions
- Using filter expressions for
troubleshooting
Module 14:
Customizing Wireshark
- Configuring profiles
- Coloring rules for quick analysis
- Creating custom columns and layouts
Module 15:
Security and Anomaly Detection
- Detecting suspicious traffic
patterns
- Identifying port scans and unusual
protocol behavior
- Introduction to encrypted traffic
analysis
Module 16:
Real-World Troubleshooting Scenarios
- Slow file transfer diagnosis
- Voice over IP (VoIP) analysis
basics
- Detecting misconfigurations and
faulty equipment
Final
Assessment
Review and
Q&A