
2-Day Instructor-Led Hands-On Lab Course
Available through Web-Based Live Delivery or On-Site Delivery
Minimum 10 Students – Maximum 16 Students
What Students are saying about this class
- “Best Wireshark course on the market – bar none!”
- “Instructor has great depth on the topics and can present them in terms and uses examples that simplify.”
- “The instructor ensures that the students understand the current topic before moving to the next.”
- “The course material was well thought out, especially the labs.”
- “Labs were very well organized, and the content was done very well as well.”
- “Instructor has a lot of knowledge, and is able to transmit it without becoming boring. He knows very well how to keep the attention from the audience. You are one of the best online instructors I’ve had, good job!”
Course Description
Wireshark is one of the most powerful tools available to network technicians, engineers, administrators, and support professionals—but capturing packets is only the beginning. The real skill is knowing where to capture, what to look for, how to filter the traffic, how protocols should behave, and how to turn packet evidence into useful troubleshooting conclusions.
This hands-on course builds a practical foundation in Wireshark and packet analysis using a layered approach to networking. Students learn how to configure Wireshark, capture and manage packet data, create effective filters, use statistics and visualization tools, and analyze network communications from the physical and data-link layers through IPv4, TCP, and UDP.
Throughout the course, students work directly with Wireshark and packet captures rather than simply watching demonstrations. The emphasis is on understanding what the packets prove, recognizing normal protocol behavior, identifying abnormal behavior, and using packet-level evidence to investigate real network problems.
This course helps answer questions such as:
- What is Wireshark, and why is packet analysis such a valuable networking skill?
- How should Wireshark be configured for efficient packet analysis?
- Where and how should traffic be captured to investigate a network problem?
- How can capture filters and display filters help isolate relevant traffic?
- What can packet captures tell us about Ethernet, IPv4, TCP, UDP, and network performance?
Course Objectives
Upon successful completion of this course, students will be able to:
- Develop practical, hands-on Wireshark analysis skills using the layered network protocol model:
- Analyze Layer 1 physical-interface information
- Analyze Layer 2 Ethernet communications
- Analyze Layer 3 IPv4 communications
- Analyze Layer 4 UDP and TCP communications
- Use Wireshark to investigate and analyze network problems:
- Apply Wireshark shortcuts, filters, and profiles
- Use Wireshark features and analysis tools more efficiently
- Understand how Wireshark can assist with network security analysis and monitoring.
- Identify and use the major elements, features, and functions of the Wireshark interface.
- Understand how Wireshark captures, processes, displays, and analyzes packet data.
- Examine the operation of communications protocols through packet-level analysis.
- Use Wireshark features to investigate network behavior, performance issues, and troubleshooting conditions.
Audience
This course is designed for anyone who needs a practical understanding of Wireshark and packet analysis as part of their networking responsibilities.
Ideal participants include:
- Sales and technical marketing professionals working with Internet and networking technologies
- Operations personnel responsible for network configuration, monitoring, and support
- Network design engineers who need Wireshark as a troubleshooting and analysis tool
- Technical sales professionals who need to relate networking features to actual protocol behavior
- Technical marketing professionals who want a deeper understanding of network and protocol operation
- Network administrators
The course is especially valuable for technicians, engineers, support personnel, and other networking professionals who need to move beyond assumptions and use packet evidence to understand what is actually happening on a network.
Course Prerequisites
This course is designed for anyone who needs the skills and knowledge required to use Wireshark effectively. Some previous networking or network-operations experience is helpful, but prior Wireshark experience is not required.
Students should attend with a laptop computer running Windows, macOS, or Linux.
When the course is delivered in a classroom where suitable computers are provided, a student laptop may not be required.
Course Materials
Students receive a PDF Course Student Guide. Packet captures and supporting analysis exercises are also provided through the CellStream Online School of Network Science.
Related Content
Students may benefit from first completing Hands-On TCP/IP Fundamentals, Hands-On TCP/IP and Ethernet Fundamentals, or one of CellStream’s IP Routing or Addressing 101 courses.
CellStream also offers Wireshark courses focused on different skill levels and network-analysis applications, including:
- Standard Edition Wireshark – 2-Day
- Standard Edition Wireshark – 3-Day
- Data Center Edition Wireshark – 2 day
- WLAN Edition Wireshark – 2 day
- Wireless Edition Wireshark – 2 day
- Voice Edition Wireshark – 2 day
- Advanced Packet Analysis with Wireshark – 2.5 day
- Advanced Wireshark Hackathon – 1-Day
- Wireshark Voice Analysis in a Day – 1 day
- Wireshark IPv6 Analysis in a Day – 1 day
- Wireshark Wi-Fi Analysis in a Day – 1 day
- Wireshark TCP Analysis in a Day – 1 day
- Wireshark QUIC Analysis in a Day – 1 day
Course Outline
Section 1: Course Introduction and Logistics
Section 2: Introduction to Wireshark®
- LAB 1: Installing Wireshark®
- Purpose, features, and applications of Wireshark
- Wireshark user interface and toolbar functions
- Status bar and Help resources
- Packet capture views and packet details
- LAB 2: Performing a Basic Packet Capture with Wireshark
- Working with trace files
- Common capture and analysis problems and tips for success
- File operations and merging packet capture files
- LAB 3: Saving and Loading Trace Files
- Capture filters
- LAB 4: Applying Wireshark Capture Filters
- Display filters
- LAB 5: Applying Wireshark Display Filters
- Colorizing, marking, and ignoring packets
- Using ring-buffer captures
- Section summary
Section 3: Network Baselines, Protocols, and Statistics
- Establishing network baselines
- System statistics and summary statistics
- Endpoint and conversation analysis
- Protocol hierarchy analysis
- Packet-length analysis
- Understanding the communications protocol stack
- Protocol layers and functions and the OSI model
- The TCP/IP protocol suite
- TCP/IP packet assembly
- I/O graphs, flow graphs, and applying filters
- Service response-time statistics
- Graphing TCP streams and round-trip time
- Determining which systems are generating network traffic
- Section summary
Section 4: Configuration and Command-Line Functions
- Determining where Wireshark should be installed or connected in the network
- Securing packet captures and captured network information
- Wireshark configuration profiles
- LAB 6: Creating a Custom Wireshark Profile
- Name resolution
- GeoIP translations
- Packet reassembly
- Checksum verification
- TShark command-line packet analysis
- tcpdump command-line packet capture
- dumpcap command-line packet capture
- mergecap command-line capture-file processing
- The Lua interpreter
- Section summary
Section 5: Layer 1 – The Physical Layer
- Functions of Layer 1
- Transmission types: simplex, half-duplex, and full-duplex
- T1, DS1 Super Frame, and DS1 Extended Super Frame
- Wireless physical-layer technologies
- Wired Ethernet physical-layer technologies
- Wireshark physical-layer analysis and common problems
- LAB 7: Layer 1 Analysis
- Wireless PHY analysis
- Wireless Wi-Fi layers
- IEEE 802.11 fundamentals, BSS, ESS, and standards
- Wireless operations, beacons, and management frames
- LAB 8: Wireless Data Capture
- Section summary
Section 6: Layer 2 – The Data Link Layer (Ethernet)
- Ethernet definitions, mechanisms, and relationship to the OSI model
- Ethernet sublayers and Logical Link Control
- Ethernet network topologies
- CSMA/CD and full-duplex Ethernet
- Ethernet hubs and switches
- Ethernet frame formats
- MAC addressing
- ARP, Inverse ARP, and Reverse ARP
- LAB 9: Layer 2 Ethernet Analysis
- Spanning Tree Protocol and Rapid Spanning Tree Protocol
- LAB 10: Ethernet Spanning Tree Analysis
- VLANs and VLAN Trunking Protocol
- LAB 11: Ethernet VLAN and VTP Analysis
- Section summary
Section 7: Layer 3 – The Network Layer: Internet Protocol (IP)
- IPv4 protocol functions and packet format
- IPv4 addressing, reserved addresses, and broadcast addresses
- IP routing
- IP packet fragmentation
- LAB 12: IP Fragmentation Analysis
- ICMP operation, packet format, and troubleshooting
- LAB 13: ICMP Troubleshooting
- LAB 14: Analyzing Layer 3 Errors
- Section summary
Section 8: Layer 4 – The Transport Layer: TCP and UDP
- TCP protocol characteristics and segment format
- TCP connection states
- The TCP three-way handshake
- TCP sockets
- TCP segmentation
- LAB 15: TCP Three-Way Handshake Analysis
- TCP flow control and sliding windows
- Packet loss, retransmissions, and TCP slow start
- The Nagle algorithm
- LAB 16: TCP Sliding Window Analysis
- UDP operation and characteristics
- LAB 17: UDP Analysis
- Section summary
The following section is included in the course materials and Online School labs but is not normally covered during classroom time.
Section 9: Using Wireshark® for Troubleshooting Networks
- Troubleshooting planning and strategies
- Using the Wireshark troubleshooting toolset
- Application types and application-related problems
- Network performance analysis, issues, and typical problems
- Bandwidth and latency
- TCP performance and analysis tips
- LAB: Case Study #1
- LAB: Case Study #2
- Section summary
Course Availability
Contact us for schedule dates and times via our contact form or through the details provided on the page.
View the course calendar and browse for our schedule. It will show scheduled courses and available dates for scheduling.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

