Wireshark Jumpstart : Master Key Tasks for Network Troubleshooting
by Laura Chappell, 10:00am 05/26/2009
Live Seminar Traning: chappellseminars.com
On-Demand Training: chappellU.com
www.cacetech.com / SharkfestGerald Comb
Network analysis is a FIRST RESPONDER task
Where the problem is
o Key Tasks
- Place the analyzer appropriately
- Focus on "the whiner" - Go to customer (complaining)
- Get out your baselinesFilter on specific conversations or types of traffic
- Look for "hot" problems - fast transmission
- Create key graphs - I/O, TCP, Latency, Time sequence graph,
o Hanging off a Switch
multicast, broadcast, unknown
- Install Analyzer on Host / Fred
- Hubbing Out (Half-Duplex) : adding Hub between Switch and Fred
- Tap In (Full-Duplex) : FDX Tap / NetOptics, - Aggregating Full-Duplex Tap
- Port Spanning
o What about Wireless
- AirPcap (USB H/W)
- WI Spy
o Busy Networks
- Suck it up...disable unnecessary functions (live display, name resolution, etc.)
- Use capture filters
- Try saving to file sets (she loves this)
- Analyzer naked with tshark (CLI)
- TurboCap (www.cacetech.com) : H/W solution
o tshark
tshark -h
tshark -D (interface list)
tshark -i
tshark -f
tshark -c
tshark -w
by Laura Chappell, 10:00am 05/26/2009
Live Seminar Traning: chappellseminars.com
On-Demand Training: chappellU.com
www.cacetech.com / SharkfestGerald Comb
Network analysis is a FIRST RESPONDER task
Where the problem is
o Key Tasks
- Place the analyzer appropriately
- Focus on "the whiner" - Go to customer (complaining)
- Get out your baselinesFilter on specific conversations or types of traffic
- Look for "hot" problems - fast transmission
- Create key graphs - I/O, TCP, Latency, Time sequence graph,
o Hanging off a Switch
multicast, broadcast, unknown
- Install Analyzer on Host / Fred
- Hubbing Out (Half-Duplex) : adding Hub between Switch and Fred
- Tap In (Full-Duplex) : FDX Tap / NetOptics, - Aggregating Full-Duplex Tap
- Port Spanning
o What about Wireless
- AirPcap (USB H/W)
- WI Spy
o Busy Networks
- Suck it up...disable unnecessary functions (live display, name resolution, etc.)
- Use capture filters
- Try saving to file sets (she loves this)
- Analyzer naked with tshark (CLI)
- TurboCap (www.cacetech.com) : H/W solution
o tshark
tshark -h
tshark -D (interface list)
tshark -i
tshark -f
tshark -c
tshark -w
No comments:
Post a Comment