Sie sind auf Seite 1von 8

WSU03

WSU03: Wireshark Troubleshooting


Network Performance

Appendix A:
Wireshark Lab
Exercises
Wireshark University™

Slow Browsing
Trace File: extra01.pcap

This trace begins with a really slow DNS response. In fact, the client
sends out two DNS queries. When the first DNS response arrives, the
client shuts down the listening port and responds to the second DNS
response with an ICMP Destination Unreachable/Port Unreachable. How
much delay was caused by packet loss?

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-2


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

DHCP Slow
Trace File: misc04.pcap

You know it's going to be a bad day when the first one you talk to ignores you. In this
case the client sends a DHCP Discover out and waits six seconds without a reply (you
could hear a pin drop). When the server does finally answer the client already has
another Discover queued up and ready to send – out it goes. Let's hope the rest of the
day goes better.

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-3


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

Bad FTP
Trace File: extra03.pcap

This is an interesting trace of an FTP file upload process that seemed to


take forever and then generated an error. What happened here? Can you
figure out which direction packet loss must have occurred on?

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-4


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

FTP Fail
Trace File: extra04.pcap

– An FTP upload fails. Where is the fault?

• The client?
• The server?
• The network?
• The application?

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-5


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

POST no Bills
Trace File: extra05.pcap

HTTP clients use the POST command to send data to HTTP servers. In this case, the
client does not receive the expected confirmation message.

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-6


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

Poisoned
Trace File: sym-404.pcap

A system appears to have been infected with a virus. After checking the system, you
notice that the virus detection software is out-of-date even though it is set up for
automatic update. You want to analyze the update process to ensure it is working
properly.

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-7


© 2007 Protocol Analysis Institute, Inc.
Wireshark University™

Client Frustrated
Trace File: extra07.pcap

The user complains that the “network is down.” You have captured the traffic as the
client tries to connect to a web server.

Step 1. Open the trace file listed above.

Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.

Notes:

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

_______________________________________________

WSU03: Wireshark Troubleshooting Network Performance - Appendix A Page A-8


© 2007 Protocol Analysis Institute, Inc.

Das könnte Ihnen auch gefallen