
3-Day Instructor-Led Hands-On Lab Course
Available through Web-Based Live Delivery or On-Site Delivery
Minimum 10 Students – Maximum 20 Students
What Students are saying about this class
- “I thought the Instructor was excellent. He was keen for interaction, happy to discuss and check we understood and improve course content.”
- “Very satisfied, is the best course I have ever done. [I]t is very well organized , the [online] lab is easy to use and very good structured. The [instructor]’s knowledge and teaching methods are awesome .”
- “perfect training and trainer”
- “El instructor demostraba un amplio conocimiento de la herramienta que ayudaba a la comprensión de las clases y a la resolución de dudas. Además tiene buenas dotes de comunicación que hacen que se mantenga la atención durante toda la clase.” [Translated: The instructor demonstrated a broad knowledge of the tool that helped with the understanding of the classes and the resolution of doubts. He also has good communication skills that keep the attention throughout the class.]
Course Description
Wireshark is one of the most important tools available to network technicians, engineers, administrators, support professionals, and anyone responsible for understanding what is actually happening on a network. Capturing packets, however, is only the beginning. Effective packet analysis requires knowing where to capture, what traffic to examine, how to isolate the packets that matter, how protocols should behave, and how to use packet evidence to identify the cause of network problems.
This comprehensive hands-on course develops practical Wireshark and packet-analysis skills using the layered networking model. Students learn how to configure and use Wireshark effectively, capture and manage network traffic, create useful capture and display filters, establish network baselines, use statistics and visualization tools, and analyze communications from the physical and data-link layers through IPv4, TCP, and UDP.
The three-day format provides additional time to apply these skills to network troubleshooting and performance analysis. Students progress from understanding individual packets and protocol behavior to examining conversations, identifying symptoms, evaluating performance, and working through troubleshooting case studies based on packet-level evidence.
Throughout the course, students work directly with Wireshark and packet captures rather than simply watching demonstrations. The goal is to develop a repeatable analysis process that helps students distinguish normal network behavior from abnormal behavior and use the packets to determine what happened, where it happened, and what the evidence actually proves.
This course helps answer questions such as:
- What is Wireshark, and why is packet analysis such a valuable networking skill?
- How should Wireshark be configured for efficient packet analysis?
- Where should packet captures be taken to investigate network problems?
- How can capture filters and display filters isolate relevant network traffic?
- What can packets reveal about Ethernet, IPv4, TCP, UDP, and network performance?
- How can Wireshark statistics and graphs help identify network behavior and performance problems?
- How can packet-level evidence be incorporated into a structured troubleshooting process?
Course Objectives
Upon successful completion of this course, students will be able to:
- Develop practical, hands-on Wireshark analysis skills using the layered network protocol model:
- Analyze Layer 1 physical-interface information
- Analyze Layer 2 Ethernet communications
- Analyze Layer 3 IPv4 communications
- Analyze Layer 4 UDP and TCP communications
- Use Wireshark to investigate and analyze network problems:
- Apply Wireshark shortcuts, filters, and profiles
- Use Wireshark features and analysis tools efficiently
- Understand how Wireshark can assist with network security analysis and monitoring.
- Identify and use the major elements, features, and functions of the Wireshark interface.
- Understand how Wireshark captures, processes, displays, and analyzes packet data.
- Examine the operation and interaction of communications protocols through packet-level analysis.
- Use Wireshark features to investigate network behavior, performance issues, and troubleshooting conditions.
Audience
This course is designed for anyone who needs a solid and practical understanding of Wireshark and packet analysis as part of their networking responsibilities.
Ideal participants include:
- Sales and technical marketing professionals working with Internet and networking technologies
- Operations personnel responsible for network configuration, monitoring, and support
- Network design engineers who need Wireshark as a troubleshooting and analysis tool
- Technical sales professionals who need to relate networking features to actual protocol behavior
- Technical marketing professionals who want more than a basic understanding of Wireshark
- Network administrators
The course is especially valuable for technicians, engineers, test personnel, customer-support professionals, and network operations staff who need to use packet-level evidence to investigate network behavior and troubleshoot problems.
Course Prerequisites
This course is designed for anyone who needs the skills and knowledge required to use Wireshark effectively. Some previous networking or network-operations experience is helpful, but prior Wireshark experience is not required.
Students should attend with a laptop computer running Windows, macOS, or Linux.
When the course is delivered in a classroom where suitable computers are provided, a student laptop may not be required.
Course Materials
Students receive a Course Student Guide and Lab Guide. Packet captures and supporting analysis exercises are also provided through the CellStream Online School of Network Sciences.
Related Content
While not required, students may benefit from Students may benefit from first completing Hands-On TCP/IP Fundamentals, Hands-On TCP/IP and Ethernet Fundamentals, or one of CellStream’s IP Routing or Addressing 101 courses.
CellStream also offers Wireshark courses focused on different skill levels and network-analysis applications, including:
- Wireshark QUIC Analysis in a Day – 1 day
- Standard Edition Wireshark – 2-Day
- Standard Edition Wireshark – 3-Day
- Data Center Edition Wireshark – 2 day
- WLAN Edition Wireshark – 2 day
- Wireless Edition Wireshark – 2 day
- Voice Edition Wireshark – 2 day
- Advanced Packet Analysis with Wireshark – 2.5 day
- Advanced Wireshark Hackathon – 1-Day
- Wireshark Voice Analysis in a Day – 1 day
- Wireshark IPv6 Analysis in a Day – 1 day
- Wireshark Wi-Fi Analysis in a Day – 1 day
- Wireshark TCP Analysis in a Day – 1 day
Course Outline
Section 1: Course Introduction and Logistics
Section 2: Introduction to Wireshark®
- LAB 1: Installing Wireshark®
- Purpose, features, and applications of Wireshark
- Wireshark user interface and toolbar functions
- Status bar and Help resources
- Packet capture views and packet details
- LAB 2: Performing a Basic Packet Capture with Wireshark
- Working with trace files
- Common capture and analysis problems and tips for success
- File operations and merging packet capture files
- LAB 3: Saving and Loading Trace Files
- Capture filters
- LAB 4: Applying Wireshark Capture Filters
- Display filters
- LAB 5: Applying Wireshark Display Filters
- Colorizing, marking, and ignoring packets
- Using ring-buffer captures
- Section summary
Section 3: Network Baselines, Protocols, and Statistics
- Establishing network baselines
- System statistics and summary statistics
- Endpoint and conversation analysis
- Protocol hierarchy analysis
- Packet-length analysis
- Understanding the communications protocol stack
- Protocol layers and functions and the OSI model
- The TCP/IP protocol suite
- TCP/IP packet assembly
- I/O graphs, flow graphs, and applying filters
- Service response-time statistics
- Graphing TCP streams and round-trip time
- Determining which systems are generating network traffic
- Section summary
Section 4: Configuration and Command-Line Functions
- Determining where Wireshark should be installed or connected in the network
- Securing packet captures and captured network information
- Wireshark configuration profiles
- LAB 6: Creating a Custom Wireshark Profile
- Name resolution
- GeoIP translations
- Packet reassembly
- Checksum verification
- TShark command-line packet analysis
- tcpdump command-line packet capture
- dumpcap command-line packet capture
- mergecap command-line capture-file processing
- The Lua interpreter
- Section summary
Section 5: Layer 1 – The Physical Layer
- Functions of Layer 1
- Transmission types: simplex, half-duplex, and full-duplex
- T1, DS1 Super Frame, and DS1 Extended Super Frame
- Wireless physical-layer technologies
- Wired Ethernet physical-layer technologies
- Wireshark physical-layer analysis and common problems
- LAB 7: Layer 1 Analysis
- Wireless PHY analysis
- Wireless Wi-Fi layers
- IEEE 802.11 fundamentals, BSS, ESS, and standards
- Wireless operations, beacons, and management frames
- LAB 8: Wireless Data Capture
- Section summary
Section 6: Layer 2 – The Data Link Layer (Ethernet)
- Ethernet definitions, mechanisms, and relationship to the OSI model
- Ethernet sublayers and Logical Link Control
- Ethernet network topologies
- CSMA/CD and full-duplex Ethernet
- Ethernet hubs and switches
- Ethernet frame formats
- MAC addressing
- ARP, Inverse ARP, and Reverse ARP
- LAB 9: Layer 2 Ethernet Analysis
- Spanning Tree Protocol and Rapid Spanning Tree Protocol
- LAB 10: Ethernet Spanning Tree Analysis
- VLANs and VLAN Trunking Protocol
- LAB 11: Ethernet VLAN and VTP Analysis
- Section summary
Section 7: Layer 3 – The Network Layer: Internet Protocol (IP)
- IPv4 protocol functions and packet format
- IPv4 addressing, reserved addresses, and broadcast addresses
- IP routing
- IP packet fragmentation
- LAB 12: IP Fragmentation Analysis
- ICMP operation, packet format, and troubleshooting
- LAB 13: ICMP Troubleshooting
- LAB 14: Analyzing Layer 3 Errors
- Section summary
Section 8: Layer 4 – The Transport Layer: TCP and UDP
- TCP protocol characteristics and segment format
- TCP connection states
- The TCP three-way handshake
- TCP sockets
- TCP segmentation
- LAB 15: TCP Three-Way Handshake Analysis
- TCP flow control and sliding windows
- Packet loss, retransmissions, and TCP slow start
- The Nagle algorithm
- LAB 16: TCP Sliding Window Analysis
- UDP operation and characteristics
- LAB 17: UDP Analysis
- Section summary
Section 9: Using Wireshark® for Troubleshooting Networks
- Troubleshooting planning and strategies
- Using the Wireshark troubleshooting toolset
- Application types and application-related problems
- Network performance analysis, issues, and typical problems
- Bandwidth and latency
- TCP performance and analysis tips
- LAB: Case Study #1
- LAB: Case Study #2
- Optional LAB: Case Study #3
- Section summary
Course Availability
Contact us for schedule dates and times via our contact form or through the details provided on the page.
View the course calendar and browse for our schedule. It will show scheduled courses and available dates for scheduling.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

