Wireshark fundamentals
Incidents become easier to analyse when you have useful signals. Structure monitoring and the examination of technical information to identify anomalies. Strengthen your ability to guide investigations and discuss service status.
- Duration
- 4 days 28 hours
- Code
- WSK01FR Code
Presentation
Wireshark is free packet analysis software used particularly for troubleshooting and analysing network traffic. This course teaches you to master Wireshark features for in-depth analysis of your networks and their faults.
Objectives
By the end of the course, participants will have a sound command of Wireshark to analyse network traffic in depth and identify the main sources of network faults. Analysis focuses primarily on wired Ethernet, IP, TCP and UDP, together with the main protocols used in TCP/IP.
Program
- The Wireshark interface.
- How to capture network traffic.
- Creating and using capture filters.
- Managing preferences and capture options.
- Colouring frames to distinguish traffic streams.
- Creating and using display filters.
- Creating user profiles.
- Saving and printing captures.
- Layer 2 analysis in switched Ethernet.
- Analysing ICMP traffic.
- Analysing ARP traffic.
- Analysing IP traffic.
- Analysing UDP traffic.
- Analysing TCP traffic.
- Analysing application traffic:
- DNS
- DHCP
- HTTP
- FTP
- Statistics and graphs.
- Introduction to command-line tools:
- wireshark.exe
- tshark.exe
- dumpcap.exe
- capinfos.exe
- editcap.exe
- mergecap.exe
- text2pcap.exe
- rawshark.exe
Audience
IT asset managers.
Prerequisites
Good knowledge of Ethernet and TCP/IP networks.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en