
2-Day Instructor-Led Hands-On Lab Course
Available through Web-Based Live Delivery or On-Site Delivery
Minimum 10 Students – Maximum 20 Students
What Students are Saying about This Class:
- “Andrew is a great instructor. I thoroughly enjoyed the Wireshark for Data Center course. His knowledge in this area and his ability to relay tips made this course well worth the time. I hope that I have the opportunity to take another course from him.”
- “It was a great overall experience! I used Wireshark but never had a formal training about it and this one really helped me learned a lot about the tool. We deal with network testing and automation at an enterprise level in the team and so having to get this type of training is very valuable in our daily tasks and troubleshooting of issues. The [Instructor] was great! Hopefully I’ll be able to avail more related training in the future. Thank you!”
- “Class/Instructor is great, I can certainly apply what I’ve learned to my work.”
- “Instructor presented materials professionally and complete overview of the material.”
- “Overall I was very please[d] with both the content and delivery method of the course. Also, the instructor was very knowledgeable and knew his subject matter well. I’d recommend this course to others.”
Course Description
Modern data-center networks carry large volumes of business-critical traffic, and when performance or connectivity problems occur, assumptions are rarely enough. Wireshark provides network engineers, technicians, administrators, test teams, and support personnel with the packet-level evidence needed to understand what is actually happening between systems.
The Wireshark Data Center Edition combines practical Wireshark and TCP/IP analysis skills with a focused examination of data-center storage networking. Students learn how to capture, filter, visualize, and analyze network traffic while exploring Ethernet, IPv4, TCP, UDP, SCSI, iSCSI, Fibre Channel, Fibre Channel over Ethernet, and Fibre Channel transport across IP networks.
Students use a layered approach to packet analysis, beginning with the physical and Ethernet layers and progressing through IPv4 and transport-layer behavior before examining data-center-specific protocols. Particular attention is given to the relationship between TCP behavior, packet loss, retransmissions, flow control, bandwidth, latency, and storage-network performance.
This is a hands-on course. Students work directly with Wireshark, packet captures, analysis tools, protocol traces, and troubleshooting case studies to develop skills they can apply to real data-center environments.
This course helps answer questions such as:
- What is Wireshark, and why is packet analysis valuable in a data-center environment?
- How should Wireshark be configured and used for effective troubleshooting?
- How can packet captures help identify TCP/IP and storage-network problems?
- How does TCP behavior affect iSCSI and other IP-based data-center communications?
- How can Wireshark expose SCSI, iSCSI, Fibre Channel, and related protocol behavior?
- How can packet analysis help identify performance problems involving bandwidth, latency, packet loss, and retransmissions?
- How can packet evidence be used to troubleshoot complex data-center communications?
Course Objectives
Upon successful completion of this course, students will be able to:
- Develop practical, hands-on Wireshark analysis skills using the layered network protocol model:
- Analyze the layered networking model and TCP/IP protocol suite
- Analyze Layer 1 physical interfaces
- Analyze Layer 2 Ethernet communications
- Analyze Layer 3 IPv4 communications
- Analyze Layer 4 UDP and TCP communications
- Analyze and dissect data-center SCSI, iSCSI, Fibre Channel, FCoE, and Fibre Channel over IP communications
- Use Wireshark to investigate and analyze network problems:
- Apply Wireshark shortcuts, filtering techniques, and profiles
- Use Wireshark capabilities more efficiently and effectively
- Understand how Wireshark can assist with network security analysis and monitoring.
- Identify and use the major elements, features, and functions of the Wireshark interface.
- Understand how Wireshark captures, processes, displays, and analyzes packet data.
- Examine the communications protocols exposed and analyzed by Wireshark.
- Use Wireshark features to investigate network issues, performance conditions, and maintenance requirements.
Audience
This course is designed for networking professionals who need a practical understanding of Wireshark and packet analysis in data-center environments.
Ideal participants include:
- Sales and technical marketing professionals working with Internet and data-center technologies
- Operations personnel responsible for network configuration, monitoring, and support
- Network design engineers who use Wireshark for troubleshooting and analysis
- Technical sales professionals who need to correlate product features with actual network and protocol behavior
- Technical marketing professionals who need more than a basic understanding of Wireshark
- Network administrators
The course is especially valuable for network engineers, data-center technicians, storage-networking personnel, test engineers, operations teams, and support professionals who need to investigate network and application behavior using packet-level evidence.
Course Prerequisites
This course is designed for anyone who needs the skills and knowledge required to use Wireshark effectively in data-center environments.
Some previous networking and operations experience is helpful, although prior Wireshark experience is not required.
Students should attend with a laptop computer running Windows, macOS, or Linux.
When the course is delivered in a classroom where suitable computers are provided, a student laptop may not be required.
Class size is limited to 20 students.
Course Materials
Students receive a Course Student Guide and Lab Guide. Packet captures and supporting analysis exercises are also provided through the CellStream Online School.
Related Content
Students may benefit from first completing Hands-On TCP/IP Fundamentals, Hands-On TCP/IP and Ethernet Fundamentals, or one of CellStream’s IP Routing or Addressing 101 courses.
CellStream also offers Wireshark courses focused on different skill levels and network-analysis applications, including:
- Standard Edition Wireshark – 2-Day
- Standard Edition Wireshark – 3-Day
- Data Center Edition Wireshark – 2 day
- WLAN Edition Wireshark – 2 day
- Wireless Edition Wireshark – 2 day
- Voice Edition Wireshark – 2 day
- Advanced Packet Analysis with Wireshark – 2.5 day
- Advanced Wireshark Hackathon – 1-Day
- Wireshark Voice Analysis in a Day – 1 day
- Wireshark IPv6 Analysis in a Day – 1 day
- Wireshark Wi-Fi Analysis in a Day – 1 day
- Wireshark TCP Analysis in a Day – 1 day
- Wireshark QUIC Analysis in a Day – 1 day
Course Outline
Section 1: Course Introduction and Logistics
Section 2: Introduction to Wireshark®
- LAB 1: Installing Wireshark®
- Purpose, features, and applications of Wireshark
- Wireshark user interface and toolbar functions
- Status bar and Help resources
- Packet capture views and packet details
- LAB 2: Performing a Basic Packet Capture with Wireshark
- Working with trace files
- Common capture and analysis problems and tips for success
- File operations and merging packet capture files
- LAB 3: Saving and Loading Trace Files
- Capture filters
- LAB 4: Applying Wireshark Capture Filters
- Display filters
- LAB 5: Applying Wireshark Display Filters
- Colorizing, marking, and ignoring packets
- Using ring-buffer captures
- Section summary
Section 3: Network Baselines, Protocols, and Statistics
- Establishing network baselines
- System statistics and summary statistics
- Endpoint and conversation analysis
- Protocol hierarchy analysis
- Packet-length analysis
- TCP/IP packet assembly
- I/O graphs, flow graphs, and applying filters
- Service response-time statistics
- Graphing TCP streams and round-trip time
- Determining which systems are generating network traffic
- Section summary
Section 4: Configuration and Command-Line Functions
- Determining where Wireshark should be installed or connected in the network
- Securing packet captures and captured network information
- Wireshark configuration profiles
- LAB 6: Creating a Custom Wireshark Profile
- Name resolution
- Packet reassembly
- Checksum verification
- TShark command-line packet analysis
- tcpdump command-line packet capture
- dumpcap command-line packet capture
- mergecap command-line capture-file processing
- Section summary
Section 5: Layer 1 – The Physical Layer
- Functions of Layer 1
- Transmission types: simplex, half-duplex, and full-duplex
- Wireshark physical-layer analysis and common problems
- LAB 7: Layer 1 Analysis
- Section summary
Section 6: Layer 2 – The Data Link Layer (Ethernet)
- Ethernet definitions, mechanisms, and relationship to the OSI model
- Ethernet sublayers and Logical Link Control
- Ethernet frame formats
- MAC addressing
- ARP, Inverse ARP, and Reverse ARP
- LAB 8: Layer 2 Ethernet Analysis
- Spanning Tree Protocol and Rapid Spanning Tree Protocol
- LAB 9: Ethernet Spanning Tree Analysis
- VLANs and VLAN Trunking Protocol
- LAB 10: Ethernet VLAN and VTP Analysis
- Section summary
Section 7: Layer 3 – The Network Layer: Internet Protocol (IP)
- IPv4 protocol functions and packet format
- IPv4 addressing, reserved addresses, and broadcast addresses
- IP routing
- IP packet fragmentation
- LAB 11: IP Fragmentation Analysis
- ICMP operation, packet format, and troubleshooting
- LAB 12: ICMP Troubleshooting
- LAB 13: Analyzing Layer 3 Errors
- Section summary
Section 8: Layer 4 – The Transport Layer: TCP and UDP
- TCP protocol characteristics and segment format
- TCP connection states
- The TCP three-way handshake
- TCP sockets
- TCP segmentation
- LAB 14: TCP Three-Way Handshake Analysis
- TCP flow control and sliding windows
- Packet loss, retransmissions, and TCP slow start
- The Nagle algorithm
- LAB 15: TCP Sliding Window Analysis
- How TCP affects iSCSI and Fibre Channel communications
- UDP operation and characteristics
- LAB 16: UDP Analysis
- Section summary
Section 9: Data Center Protocols
- Direction of data-center protocols
- SCSI and iSCSI overview
- iSCSI definition and overview
- Protocol stack, architecture, and components
- LAB 17: iSCSI Lab Experiment
- Fibre Channel
- Fibre Channel definition and overview
- Protocol stack, architecture, and components
- Fibre Channel transport options
- Option 1: Fibre Channel over Ethernet
- LAB 18: Fibre Channel over Ethernet Experiment
- Option 2: Fibre Channel over IP
- LAB 19: Fibre Channel over IP Experiment
- Option 3: Fibre Channel in IP
- Summary and comparison of Fibre Channel transport options
- Internet Storage Name Service
- Common issues, key analysis points, and troubleshooting tips
Section 10: Using Wireshark® for Troubleshooting Networks
- Troubleshooting planning and strategies
- Using the Wireshark troubleshooting toolset
- Application types and application-related problems
- Network performance analysis, issues, and typical data-center problems
- Bandwidth and latency
- TCP performance and data-center analysis tips
- LAB: Case Study #1
- LAB: Case Study #2
- LAB: Data Center Case Study #3
- Section summary
Course Availability:
Contact us for schedule dates and times via our contact form or through the details provided on the page.
View the course calendar and browse for our schedule. It will show scheduled courses and available dates for scheduling.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

