Author name: Andrew Walding

Andrew Walding is the founder and president of CellStream, Inc., bringing more than 30 years of experience in telecommunications, broadband networking, Internet technologies, and technical education. His expertise spans network engineering, wireless and wireline communications, packet analysis, network operations, emerging technologies, and the design and delivery of advanced technical training programs. A Cisco-certified professional, IPv6-certified specialist, and CBRS Certified Professional Installer (CPI), he helps organizations and technology professionals understand, deploy, troubleshoot, and optimize modern communications networks.

Wireshark’s Slice Operator: Search Exact Bytes Without Writing a Dissector

Post Views: 172 Wireshark gives us thousands of protocol fields to filter on: But what happens when the exact information you want isn’t exposed as a field? That is where Wireshark’s Slice Operator becomes extremely useful. A slice lets you select specific bytes from a field, payload, protocol, or even the captured frame itself. For

Wireshark’s Slice Operator: Search Exact Bytes Without Writing a Dissector Read More »

, , , ,

Correlating Multiple Wireshark Captures: Follow the Same Packet Across the Network

Post Views: 211 So many times I have watched YouTube videos and read articles that jump right into Wireshark troubleshooting of multiple captures of a network conversation or event from multiple points in the network. To me, that can be unnecessarily overwhelming to those learning packet capture. In many videos, it never becomes clear why

Correlating Multiple Wireshark Captures: Follow the Same Packet Across the Network Read More »

, ,

sngrep: The SIP Troubleshooting Tool You Should Know

Post Views: 177 If you work with VoIP, and more specifically SIP long enough, eventually you find yourself staring at an INVITE, a handful of provisional responses, several IP addresses, a 200 OK, an ACK, and perhaps a BYE—and trying to mentally reconstruct what actually happened. Wireshark can certainly do this. In fact, Wireshark remains

sngrep: The SIP Troubleshooting Tool You Should Know Read More »

, , , , , , ,

Turn Wireshark Columns into Calculated Network Analytics

Post Views: 175 Most Wireshark users eventually discover Custom Columns. Instead of being limited to the standard Source, Destination, Protocol, Length, and Info columns, you can add useful fields such as: tcp.stream tcp.analysis.ack_rtt dns.qry.name vlan.id That alone can make packet analysis much easier. But in newer versions of Wireshark, Custom Columns can do much more

Turn Wireshark Columns into Calculated Network Analytics Read More »

, , ,

Native VLAN vs. Normal VLAN: What Is the Difference on a Cisco Switch?

Post Views: 222 This is a great question that is answered in my courses that teach L2 Ethernet, but I have never answered here. So let’s dive in. VLANs are one of the fundamental building blocks of Ethernet switching. They allow us to divide a physical switched network into multiple logical Layer 2 broadcast domains.

Native VLAN vs. Normal VLAN: What Is the Difference on a Cisco Switch? Read More »

, , , , , , , , ,

The Wireshark # Operator: Filter the Inner vs. Outer IP Header

Post Views: 515 Most Wireshark filters assume there is only one IP header in a packet. For example: ip.src == 10.1.1.10 works perfectly well in ordinary traffic. But what happens when the packet contains more than one IP header? That is common with technologies such as: A tunneled packet might look like this structure: Now

The Wireshark # Operator: Filter the Inner vs. Outer IP Header Read More »

, , , , ,

Where can I get PCAP Packet Captures for Learning and Exploration?

Post Views: 6,440 I am often asked this question of where to access PCAP or PCAP-NG files so that folks can explore packet captures using Wireshark.  I have always provided these resources in my Wireshark classes at the Online School, but thought I should also just list them here for public consumption. Before you click!

Where can I get PCAP Packet Captures for Learning and Exploration? Read More »

, , , ,

The Wireshark $ Operator: Build Filters Around the Packet You Click

Post Views: 746 Most Wireshark display filters use values that you type manually. For example: ip.addr == 192.168.1.100 or: tcp.stream == 14 But Wireshark has a lesser-known capability that lets you build a filter using values from the packet you currently have selected. That capability is called a field reference, and it uses the $

The Wireshark $ Operator: Build Filters Around the Packet You Click Read More »

, , ,

The Best Auto Switch Filters for Wireshark Profiles

Post Views: 314 One of the cooler features added to recent versions of Wireshark is the ability to automatically select a Configuration Profile when you open a capture file. I covered how to configure this feature in my earlier article, Automatically Switch Configuration Profiles in Wireshark. Since then, I have spent more time thinking about

The Best Auto Switch Filters for Wireshark Profiles Read More »

, ,

Why CellStream Doesn’t Fill This Site With Ads — and How You Can Help

Post Views: 1,658 If you spend much time on CellStream.com, you may notice something that has become increasingly unusual on the Web: We don’t fill our articles with advertising. There are no advertisements interrupting a Wireshark tutorial. No pop-up covering the network diagram you’re trying to read. No video suddenly playing while you’re studying IPv6.

Why CellStream Doesn’t Fill This Site With Ads — and How You Can Help Read More »

, , , ,

Why Broadband Technicians and Network Engineers Should Install WSL

Post Views: 349 If you work in broadband or networking and use a Windows laptop, you probably already have a pretty capable troubleshooting platform. Windows gives you tools such as ping, tracert, nslookup, PowerShell, SSH, and a growing collection of useful networking commands. Add Wireshark, Nmap, and a few other utilities and you can do

Why Broadband Technicians and Network Engineers Should Install WSL Read More »

, , ,

Our BGP Lab Series is Up

Post Views: 274 Network Engineers and folks learning networking – my BGP Lab series is now available – you will find them here. There are three Labs that include GNS3 topologies, and PCAPS to emulate and capture these awesome labs. Starting with Basic, then looking at Multihop eBGP, then examining the protocol with Wireshark, then

Our BGP Lab Series is Up Read More »

, , , , , , , , , ,

CSI-HO-016 – Hands-On IPv6 – 2 Day

Post Views: 24,014 IPv6 Addressing, Operation, Routing, Packet Analysis, and Troubleshooting 2-Day Instructor Led Hands On Lab ClassAvailable in either Web Based delivery or On-Site DeliveryMinimum 10 students – Maximum 16 students What Students say about this course: Course Description IPv6 is no longer a technology that network professionals are simply preparing for. It is

CSI-HO-016 – Hands-On IPv6 – 2 Day Read More »

, ,

IPv6 Hands-On Training: IPv6 Is Here — Are Your Skills Ready?

Post Views: 32,046 Check out these additional IPv6 Resources: Our IPv6 overview course at Udemy Our IPv6 Custom Profiles for Wireshark Our IPv6 classes at the Online School Years ago, the networking industry talked about IPv6 as something that was coming. That conversation is over. IPv6 is here. IPv6 is deployed across service provider, mobile,

IPv6 Hands-On Training: IPv6 Is Here — Are Your Skills Ready? Read More »

,
Scroll to Top