introduction to wireshark making sense of the matrix

17
Introduction to Wireshark Making Sense of the Matrix

Upload: david-reed

Post on 12-Jan-2016

225 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Introduction to Wireshark Making Sense of the Matrix

Introduction to Wireshark

Making Sense of the Matrix

Page 2: Introduction to Wireshark Making Sense of the Matrix

Presenter – Chris Greer

Packet Pioneer LLCNetwork Analyst - WCNA

Training and Professional ServicesNetwork and application performance analysiswww.lovemytool.comwww.brighttalk.com

Page 3: Introduction to Wireshark Making Sense of the Matrix

Housekeeping

• You can follow along with your own copy of Wireshark – www.wireshark.org

• Download the trace files we will be using at:

• www.bit.ly/packetanalysis

Page 4: Introduction to Wireshark Making Sense of the Matrix

Why packets?

• Packets Don’t Lie• We can’t fix what we can’t see• Traffic and Protocol Analysis is the most

detailed troubleshooting method

Page 5: Introduction to Wireshark Making Sense of the Matrix

Packet Collection

• Common capture methods:Span/Mirror

Tap / Aggregation Tap

Directly on the client

UTILSTAT

DUPLEXSPEED

SYSTEMRPS

CATALYST 35503

4

5

6

7

8

9

10

11

12

1

2

15

16

17

18

19

20

21

22

23

24

13

14

1 2

`

Page 6: Introduction to Wireshark Making Sense of the Matrix

Getting in the path: Span/Mirror

• Copies selected ports, hosts, vlans, or traffic patterns to a monitor port

`

Page 7: Introduction to Wireshark Making Sense of the Matrix

Getting in the path: Taps

• A tap is the best means to capture packets• Directly monitors the connection inline

`

Page 8: Introduction to Wireshark Making Sense of the Matrix

Getting in the path: Aggregation TAP

Tap OutputSPAN Output

Page 9: Introduction to Wireshark Making Sense of the Matrix

Capturing directly from client

• The protocol analyzer can be installed directly on the client – but there are several negatives to this

`

Page 10: Introduction to Wireshark Making Sense of the Matrix

Problems aren’t what they used to be

Page 11: Introduction to Wireshark Making Sense of the Matrix

QUICK, FIND THE PROBLEM!

Page 12: Introduction to Wireshark Making Sense of the Matrix

But it looks like this…

Page 13: Introduction to Wireshark Making Sense of the Matrix

Step 1: Setup your columns

Open HTTP-CNN.pcap

Page 14: Introduction to Wireshark Making Sense of the Matrix

Step 2: Configure Display Filters

Open HTTP-CNN.pcap

Page 15: Introduction to Wireshark Making Sense of the Matrix

Step 3: Find Top Talkers

Page 16: Introduction to Wireshark Making Sense of the Matrix

Step 4: Know What to Ignore

Open Slow Web Application.pcap

HTTP-CNN.pcap

Not filters.

Page 17: Introduction to Wireshark Making Sense of the Matrix

Thanks!

Enjoy the rest of Sharkfest 2015!