Speak to our team now +44 (0)1737 821590

Wireshark 101 for engineers

A 2 day
training course

Wireshark 101 training course description

Wireshark is a free network protocol analyser. This hands-on course provides a starting point for troubleshooting networks using Wireshark. The course concentrates on the Wireshark product and students will gain from the most from this course only if they already have a sound knowledge of the TCP/IP protocols.

Key outcomes from this course

By the end of the course delegates will be able to:
  • Download and install Wireshark.
  • Capture and analyse packets with Wireshark.
  • Configure capture and display filters.
  • Customise Wireshark.
  • Troubleshoot networks using Wireshark.

Wireshark 101 training course details

Who will benefit:
Technical staff looking after networks.
TCP/IP Foundation.
2 days

Training approach

This structured training course seeks to build upon workbook learning through the use of group exercises, dynamic discussion and individual tasks in order to deliver an engaging and interactive module that will ensure all candidates are able to transfer their new skills into the workplace.

Overall ratings for this course:

Course review

"Excellent course. Already told colleagues to get on it. "
M. M. Cobham Aviation Services
"Plenty of content and good structure and documentation for future reference. "
A. H-S. Optasense

Wireshark 101 training course contents

What is Wireshark?
Protocol analysers, Wireshark features, Wireshark versions, troubleshooting techniques with Wireshark.

Installing Wireshark
Downloading Wireshark, UNIX issues, Microsoft issues, the role of winpcap, promiscuous mode, installing Wireshark. Wireshark documentation and help.
Hands on: Downloading and installing Wireshark.

Capturing traffic
Starting and stopping basic packet captures, the packet list pane, packet details pane, packet bytes pane, interfaces, using Wireshark in a switched architecture.
Hands on: Capturing packets with Wireshark.

Troubleshooting networks with Wireshark
Common packet flows.
Hands on: Analysing a variety of problems with Wireshark.

Capture filters
Capture filter expressions, capture filter examples (host, port, network, protocol, worm), primitives, combining primitives, payload matching.
Hands on: Configuring capture filters.

Display filters
Applying and clearing filters. Protocol, fields, addresses, frames containing strings. Filter comparisons. Combining filters. Finding packets, marking packets.
Hands on: Configuring display filters.

Working with captured packets
Live packet capture, saving to a file, capture file formats, reading capture files from other analysers, merging capture files, finding packets, going to a specific packet, display filters, display filter expressions.
Hands on: Saving captured data, configuring display filters.

Analysis and statistics with Wireshark
Enabling/disabling protocols, user specified decodes, following TCP streams, protocol statistics, conversation lists, endpoint lists, I/O graphs, protocol specific statistics.
Hands on: Using the analysis and statistics menus.

Command line tools
Tshark, tethereal, capinfos, editcap, mergecap, text2pcap, idl2eth.
Hands on: Using tshark.

Advanced issues
802.11 issues, management frames, monitor mode, packet reassembling, name resolution, customising Wireshark.
Hands on: Customising name resolution.

Why Choose Us

SNT trainers score an average of over 90% on the three main areas of:
  • Ability to teach
  • Technical knowledge
  • Answering questions
“Excellently presented by a very knowledgeable and enthusiastic trainer.” P.D. General Dynamics

We limit our maximum class size to 8 delegates; often we have less than this. This ensures optimal interactivity between delegates and instructor.
"Excellent course. The small class size was a great benefit…" M.B. IBM

We write our own courses; courseware does not just consist of slides and our slides are diagrams not bullet point text. A typical chapter provides clearly defined objectives with a chapter overview, slides with text underneath, a quiz at the end to check the learning of the students. Hands on exercises are at the end and are used to reinforce the theory.

See Dates & Prices for this course

To enquire about this course

To reserve this course online