Troubleshooting slow networks with Wireshark // wireshark filters // Wireshark performance

  Рет қаралды 131,495

David Bombal

David Bombal

Күн бұрын

Пікірлер: 239
@SirPeterlll
@SirPeterlll 2 жыл бұрын
Yes to war stories. Maybe also examples on how to make (easy) home labs to play around with wireshark to find network and/or application issues.
@keyntankeye
@keyntankeye 2 жыл бұрын
Yea that’s a good one
@viv_2489
@viv_2489 2 жыл бұрын
Yeah real life examples
@ex7229
@ex7229 2 жыл бұрын
Excellent. I've only been a network Admin 6 months , our Network Engineer retired and I was given the position and got my CCNA. There's so much I do not know. Its overwhelming I knew bare minimum about wireshark but it helped me fix 2 things. This really helped me learn a little more and in the spirit of one of the greatest greek philosophers Seneca says "Every night before going to sleep, we must ask ourselves: what weakness did I overcome today? What virtue did I acquire? " Wireshark is a network engineer virtue as far as I am concerned.
@galloe
@galloe 8 ай бұрын
Great anecdote! Just a tiny detail, Seneca was a Roman philosopher.
@mawutorquarshie7953
@mawutorquarshie7953 2 жыл бұрын
Once again David has brought in someone experienced in wire shark to lead us into the world of Networking troubles. Thanks David.....more of this.
@oussemaghorbel7578
@oussemaghorbel7578 2 жыл бұрын
This guest is simply amazing! Each time I listen to a session and learn a lot of useful knowledge from it
@lokeahrana08
@lokeahrana08 2 жыл бұрын
After watching this video I feel like I learned something today. Thanks a lot, David for bringing such an amazing person to the show.
@dwaynesudduth1028
@dwaynesudduth1028 2 жыл бұрын
Another great collaboration by @David Bombal and @Chris Greer! The knowledge bombs dropped here are invaluable, thanks to both of you!
@mashmasho
@mashmasho 2 жыл бұрын
I’m a pretty simple person. I see David Bombal posted a video, I hit like. Haven’t even watched it yet, but I know it will be fantastic! Love your content!
@davidbombal
@davidbombal 2 жыл бұрын
Thank you so much!
@Ranjeet_88
@Ranjeet_88 2 жыл бұрын
Chris is a legend. you got to appreciate david here, even though he knows things that Chris misses sometimes he gently remind him that as a question and doesn't try to show off. Have observed this with lot of guest, quality of a great host and something we could learn. keep bringing such content David. thank you
@ervinr82
@ervinr82 2 жыл бұрын
He stirs the pot. In a good way.
@justinbridgman9503
@justinbridgman9503 2 жыл бұрын
That was brilliant, I am returning to networking after a 5 year break and this work you guys are doing has given me a real boost in confidence that I am in the right place. I really enjoyed that, that data was enlightening, accessible and useful. Also interested to hear what that config was!!! Thank you very much
@abylaurancecherian4930
@abylaurancecherian4930 2 жыл бұрын
Thanks for the wonderful session David & Chris... Looking forward for the war room sessions as well.
@jerrygawlicky8859
@jerrygawlicky8859 2 жыл бұрын
Hey David I was watching the TLS run down you did with the other SME on encryption and TLS communication. However... I noticed something in my analysis and following along with the video.,. I am gonna circle around to it today and take a second glance.. maybe check my f5 it may be effecting the handshake but.. for sure no certificate and or server done packets were within my tls handshake... just wanted to give you a heads up. Maybe they were encrypted or modified i haven't looked yet.. but none the less great stuff man... and chris is the man when it comes to wireshark and analsysis at the deep packet level. His shark fest tips have helped me identify many problems.. in the real world. Keep up the awesome freedom of knowledge you guys give and dont charge for :) Cheers!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks for commenting! Glad the content is helping you in the real world. 👍
@CK-ck9ut
@CK-ck9ut 2 жыл бұрын
Chris is one of the nicest most helpful individuals I have ever contacted.
@hamada99457
@hamada99457 2 жыл бұрын
Thanks both of you guys we need more videos on Wireshark I'm a NOC Engineer and I really want to add Wireshark to my skills as we know Wireshark helps you a lot if you know how to play with it I will join Chris Greer course maybe I will find what I'm looking for.
@MrEric377
@MrEric377 2 жыл бұрын
I have supported apps that others have built and you are 100% right. It is always the network fault as both the support personal and app developers don't want to be blamed (2 to 1). I have tried to use Wireshark in the past, but just too much info and not enough understanding. I have seen co-workers point at a random lines in Wireshark and say oh that is a network issue, but couldn't explain or prove why they know it is a network issue. For the un-trained (Like me) Wireshark is a 2 way street as it could lead to the wrong path. It is always refreshing to see how a professional packet analyst can look and filter Wireshark and (with little knowledge of the app in question) can articulate what is going on and give a reasonable path forward. Amazing, I love this discussion.
@michaeldawkins6812
@michaeldawkins6812 2 жыл бұрын
Thanks Chris and David for some great network knowledge content. One of the growing issues that I have is understanding broadcast traffic / trace coverage / segmentation (vlans).
@joerockhead7246
@joerockhead7246 2 жыл бұрын
Thanks, David, & Chris. This was great. Would love to see a lot more from Chris. BTW @ 53:20 is how I enter my passwords. :)
@DimitriPappas
@DimitriPappas 2 жыл бұрын
As a sysadmin/netadmin by trade, one skillset I've really neglected is packet capture/inspection as a means for troubleshooting & debugging or simple forensics. I normally rely on tools like Mikrotik's packet sniffer to get some basic information but this is clearly the better way to dive in and isolate the problem. Seeing all the encrypted hex traffic and mystical headers and protocols in Wireshark can be very intimidating, but the application itself seems very user-oriented and the filtering logic is very intuitive. This video has definitely sparked some interest in spending more time with wireshark as it's definitely going to be a skillset worth any effort and frustration in the learning curve, as it will save great deals of time (and probably money) in the long run. Thanks gents for the great content
@ChrisGreer
@ChrisGreer 2 жыл бұрын
You hit it Dimitri! Packet skills are very worth investing the time into.
@PowerShorts-
@PowerShorts- 2 жыл бұрын
I am teaching myself to pursue a career in cyber security. This is pure gold thank you so much!
@androidandroid1631
@androidandroid1631 2 жыл бұрын
High David and Chris, thanks a lot for the TCP Deep Dive series. It helped a lot to start find network problems with Wireshark. As always it is hard to find the needle.
@techlearner4806
@techlearner4806 10 ай бұрын
49:53 Great question David. I was thinking about this question since Chris started with HTTP. Many thanks for this absolutely must question.
@vyasG
@vyasG 2 жыл бұрын
Thank you both for this series. This is gold. Looking forward for more videos on real world experiences. Really loved the consulting scenarios. The teaser in the end was a good one. Will be curiously waiting for that story!
@dezejongeman
@dezejongeman 2 жыл бұрын
this is GOLD!!!! War stories are awsome and gets insight on how to jump into issues. slowness is the hardest.
@ThePumbaadk
@ThePumbaadk 2 жыл бұрын
Thanks Chris and David, real-time scenario would be fun to see
@jeevespreston
@jeevespreston 2 жыл бұрын
Still learning WS, very enlightening, thanks so much!!
@Mbro-dq2do
@Mbro-dq2do Жыл бұрын
Great video. Big props to Chris. I always thjought he was observing TShark on Linux using a wifi usb adapter plug in which you can. But i didnt know I could install it natively on my Dell AND my Macs without using my Linux oS. Now I can see real info and really read serious traffic. I was never seeing any ip's or anything. just a bunch a minor AP traffic. Color codes never came up but now holy shit thee amount of traffic that colorized is nuts. I can finally see what my own personal traffic looks like on the wire. LOVE these videos on TShark with chris. Thank you so much David
@jeroenvandervelden7318
@jeroenvandervelden7318 2 жыл бұрын
Great Tutorial! Would love to see a full Wireshark one on slow wifi debugging please!
@erothwell
@erothwell 2 жыл бұрын
Loving the team ups w/ Chris. I’m learning so much and subscribed to his channel too.
@upendrasingh2390
@upendrasingh2390 2 жыл бұрын
I always love to watch your channel. Every time learn new things 😃
@MeMyselfAndBob
@MeMyselfAndBob 2 жыл бұрын
Great video David! I've learned a lot, over and over again! Chris is a fantastic teacher. And yes, I can't wait to hear those war stories you've got Chris.
@niravchauhan2278
@niravchauhan2278 2 жыл бұрын
Great session.👍✌️Thank you David && Chris
@RolZuela
@RolZuela 2 жыл бұрын
Awesome video! Another overview of wireshark and fragmentation (usually over VPNs) would be awesome!
@3004Marbles
@3004Marbles 2 жыл бұрын
Nooooo! That cliffhanger was brutal! Can't wait for the next part. I want to know all about those war stories!
@carlosc3260
@carlosc3260 2 жыл бұрын
Massive thanks guys! Brilliant examples. Looking forward to more stuff in this format. That “war stories” sounds great too 👍🏼
@MK-jf1rv
@MK-jf1rv 2 жыл бұрын
Great content👍 Thanks for coming back to networking in between we lost you David🙏🥰🥰
@davidbombal
@davidbombal 2 жыл бұрын
Thank you. I will never forget networking 😀
@MK-jf1rv
@MK-jf1rv 2 жыл бұрын
@@davidbombal Thank you🙏🥰🥰
@ontrucktoit6166
@ontrucktoit6166 2 жыл бұрын
I think I know what you mean, but on the other hand networking is everywhere :)
@delyansivchev5155
@delyansivchev5155 2 жыл бұрын
Very interesting lecture,.... Would be really useful though as continuation to have some inside tips about how to stitch packet traces/packets inside traces taken from different parts of the network and endpoints with focus on TCP sequencing and session stitching between those different captures - as most of the time to prove the point of application or network issue it is often needed to take packet traces on network devices too.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
I really like this suggestion. Noted!
@dandele123
@dandele123 2 жыл бұрын
this video is fantastic, would love to hear more about wireshark and war stories from Chris
@CyberxploitHausa
@CyberxploitHausa 2 жыл бұрын
You nailed it David. Thanks for sharing these type of people to the community. ♥️🇳🇬
@rohanmahakal8113
@rohanmahakal8113 2 жыл бұрын
Worth watching saved so much of time figuring out certain things in WS.
@Fz3r0_OPs
@Fz3r0_OPs 2 жыл бұрын
Thank you very very much David and Chris, this series of videos of Wireshark are so usefull for me. Thanks to both for sharing your knowledge, greetings from Riviera Maya :)
@Bold1c1u
@Bold1c1u 2 жыл бұрын
You and your guests are the best. i learn so much stuff about the networking field in a fan and entertaining maner.
@szali923
@szali923 2 жыл бұрын
Great video. Love these in depth videos about Wireshark with Chris. Keep them coming, and thanks.
@Gh0_-st
@Gh0_-st 2 жыл бұрын
i love how i was just going to call my isp when i just got this video notification 😂
@davidbombal
@davidbombal 2 жыл бұрын
That's great! 😂
@Mike.Kachar
@Mike.Kachar 2 жыл бұрын
David / Chris; I love these Wireshark videos you've been doing. Even tho a lot of it I've already picked up on my own, just by running pcap's working as a Sec Analyst in PCI, there's still a bunch of stuff that I've learned watching these videos. Please oh please...KEEP 'EM COMING! You rock, @Chris Greer - thanks!!
@lewis5754
@lewis5754 2 жыл бұрын
Thanks for the great presentation Chris and David. Really useful. Would love to hear some war stories!
@jerrygawlicky8859
@jerrygawlicky8859 2 жыл бұрын
Chris.. You guys should setup a lab with eve ng and simulate congestion and show how the congestion notifications work and how the window size works both in a compatible setup with ecn and ecw and one without the capability... and let me know if you guys do :) Would love to be a part of it or follow it.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
That is a great idea. Actually I was thinking it is time for an example with ECN.
@akshaypotdar1840
@akshaypotdar1840 2 жыл бұрын
Thanks David for all your work and the free infomraiton you provide. Could you do a video on industrial networks profinet, EtherntIP etc., from network security point of view, please?
@Pursuitdnb
@Pursuitdnb 2 жыл бұрын
This is awesome David! This could have saved tons of time and headaches in the past!
@viv_2489
@viv_2489 2 жыл бұрын
This is class and great tutorial.. Chris is master of his craft
@denniessundia1912
@denniessundia1912 2 жыл бұрын
Nice content...well explained. Especially the part where network guys were exonerated. Would you find a pcap to show how to prove its the application/server that has the lag. I would be helpful...
@Odim65
@Odim65 2 жыл бұрын
DAVID amazing content as always with Chris. If it is possible if you guys can make DNS deep dive and troubleshooting with Wireshark, especially those related to active directory.
@davidmendoza6768
@davidmendoza6768 2 жыл бұрын
I'd love to hear the war stories!
@davidbombal
@davidbombal 2 жыл бұрын
You are guilty until proven innocent! The network is slow! But is it actually a network issue? Or is it an application issue. Chris Greer explains. // MENU // 00:00 ▶ Introduction 00:26 ▶ Intro 00:35 ▶ Wireshark filters introduction 02:20 ▶ Regular IP filter 05:28 ▶ Common filters 07:10 ▶ Operators in filters 08:19 ▶ Where to get the filter Power Point 08:55 ▶ Filter shortcuts 11:20 ▶ Filter buttons 12:10 ▶ TCP analysis flags 15:16 ▶ Filter buttons (cont'd) 17:15 ▶ TCP reset 18:35 ▶ How to apply filter as display filter 20:08 ▶ Experience vs Theory 22:19 ▶ Special filters 29:00 ▶ Time filters 38:22 ▶ Consulting scenario 49:45 ▶ HTTPS consulting scenario 55:33 ▶ Other filters 56:46 ▶ How to simplify p-caps 59:29 ▶ Signature filters 01:01:39 ▶ Quick recap 01:02:16 ▶ Conclusion // MY STUFF // www.amazon.com/shop/davidbombal // SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin: kzbin.info //CHRIS GREER // Udemy course: davidbombal.wiki/chriswireshark LinkedIn: www.linkedin.com/in/cgreer/ KZbin: kzbin.info Twitter: twitter.com/packetpioneer // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
@YouTubeKing506
@YouTubeKing506 2 жыл бұрын
Please say how much time it takes to crack wifi password with hashcat brude force'. -a
@johnwesley256
@johnwesley256 2 жыл бұрын
Great Video! Most of my DDOS attacks come from TCP. Also a lot of malware and virus's I've caught come from directX JavaScript and Java which usually comes from ads. You don't even need to click the ad, it just needs to load on your browser
@hareshsingh3144
@hareshsingh3144 2 жыл бұрын
please upload short videos max 30min
@jeevespreston
@jeevespreston 2 жыл бұрын
In my world we call that MTTI, Mean Time to Innocence!! it's always the network, until you prove that it's not...
@PowerShorts-
@PowerShorts- 2 жыл бұрын
Can you please please have him look at malicious activity.
@JJ-nv3tv
@JJ-nv3tv 2 жыл бұрын
Really good info here, some I use already quite a bit. Wish they cleaned up the audio on this though
@toromac9786
@toromac9786 2 жыл бұрын
I recently had to use Wireshark at work - had no idea what I was doing (still don't) but think this should prove helpful (Trying to track down Rx Length errors)
@shaan885
@shaan885 2 жыл бұрын
Like always great contents! Thanks to you both for this WS series and many more. ❤😊
@majiddehbi9186
@majiddehbi9186 2 жыл бұрын
Great initiative as i said knowing wirshark is so importante thx Mr Bombal, Chris is awesome with his claire explanation i love this topic
@barkataligulzari6516
@barkataligulzari6516 2 жыл бұрын
Thanks David and Chris. Yes to War story
@MisterV..
@MisterV.. 2 жыл бұрын
I love to learn Wireshark. Very great video. Thanks
@depon91
@depon91 2 жыл бұрын
I was checking your video about wireshark early today and now here is the other one
@ICOFRITE
@ICOFRITE 2 жыл бұрын
David asks all the right questions
@MrBitviper
@MrBitviper 2 жыл бұрын
awesome content as always and and it's always great to see content from chris btw you're getting pretty close to 1 million subs David hope you get there real soon
@nghiaduy6044
@nghiaduy6044 2 жыл бұрын
Thank you guys for keeping on this great series!!
@mbnyc5401
@mbnyc5401 2 жыл бұрын
FYI. In software dev, single = is assignment . Balance=5. Double equals, tests for that value. If(balance ==5).
@JonMajorCCIE47884
@JonMajorCCIE47884 2 жыл бұрын
I came here for a casual watch, but as with every freaking Chris Greer video, here I am taking notes.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Really glad you like the content Jon! Thanks for the comment.
@JonMajorCCIE47884
@JonMajorCCIE47884 2 жыл бұрын
@@ChrisGreer no sir, thank you lol. I’ve taken to recommending everyone on my team watch your content.
@WilverSanchez-nb8sw
@WilverSanchez-nb8sw Жыл бұрын
Yes to war stories! Looking forward to watch the video!
@homayounshokri5041
@homayounshokri5041 2 жыл бұрын
Great , informative and practical as usual Can you make video on IPsec and IKE like tlss handshake one from almost two weeks ago?
@davidbombal
@davidbombal 2 жыл бұрын
Great suggestion!
@tahersadeghi6773
@tahersadeghi6773 Жыл бұрын
Thank you, David and Chris.
@James_Knott
@James_Knott 2 жыл бұрын
With TCP, some packet loss is normal. In fact, it's required for flow control to work.
@ccnp2009
@ccnp2009 Жыл бұрын
Wireshark and Tcpdump are IT Security Engineers handed tool to validate traffic. Awesome Video
@outerheaven01
@outerheaven01 2 жыл бұрын
Yes! War stories and a run down on the profile on Chris Wireshark (specially the buttons he has)
@keratishvili
@keratishvili 2 жыл бұрын
Hey David could you make networking observing for ebpf systems?
@dhakalmanish
@dhakalmanish 2 жыл бұрын
Thank You David and Chris! Great Video
@ayoluca1
@ayoluca1 2 жыл бұрын
One of the first CCIE legend said once that wireshark is useless, it's just another product with great marketing out there mostly for network engineers, cause with no wireshark , issues can be fixed, and while we dedicate and spend "time" to analyze the data, the outage is there, I don't and I dint like what he said, but being in tshot cases for more than 10 years, I just use wireshark for fun, I don't know honestly ...
@Xotty
@Xotty 2 жыл бұрын
Love to watch Chris. Learning an awful lot. And yes, please do a "war stories" video :)
@johnwesley256
@johnwesley256 2 жыл бұрын
A decade ago I was using WPE for my filtering which was great because it targeted an individual application. Now uh days browsers and many other apps use multiple processes so it's not practical 2day. In programming = would be to set a value to a variable. == Means "is equal to". === Means "is exactly equal to" usually for Case Sensitive issues. I'm thinking these are the same. War stories are great!
@Delijohn
@Delijohn Жыл бұрын
Chris Greer is amazing! Thanks for this!
@cyphodias1640
@cyphodias1640 2 жыл бұрын
Thanks again David and Chris for the incredible information. I’m also a yes please to a war stories video. 👍
@nellermann
@nellermann 2 жыл бұрын
great tool for solving or proving rather SIP and voip issues is not the network.
@alejandrorodriguez3771
@alejandrorodriguez3771 2 жыл бұрын
This is what I was hoping from a long time ago.
@fritzbiederstadt4869
@fritzbiederstadt4869 2 жыл бұрын
You guys are killing me...It's not that I don't agree. I totally agree with Wireshark is the industry standard. Unfortunately for for me, the organization I work for got sold that "Netscout can do anything Wireshark can do". So they no longer allow use to use Wireshark...I like Netscout, but its simply not optimized for on the fly and deep packet inspection, research, etc. I've used various Sniffer Pro solutions, Domino Nas, EtherPeek, and a few others...Nothing does it as well as Wireshark! OK...I feel a little better.
@shappyify
@shappyify 2 жыл бұрын
I would like to hear an example of when you actually encountered a problem with the network and how you found that.
@TastyChickenLegs
@TastyChickenLegs 2 жыл бұрын
This guy is amazing. The amount I learned in this one video is pretty amazing. Thanks
@soma972
@soma972 2 жыл бұрын
Thank you very beaucoup !! And the chapters is very useful.
@zubairzonbarkar3358
@zubairzonbarkar3358 2 жыл бұрын
This was amazing Can we get to see deep dive in ssl(tls) and ssh
@dden-qz8ym
@dden-qz8ym 2 жыл бұрын
This is very good stuff. Please keep it up.
@SnortDefence
@SnortDefence 2 жыл бұрын
It would be good if attach the pcap for side by side analysis
@debarghyadasgupta1931
@debarghyadasgupta1931 2 жыл бұрын
It's killer content as always. Thanks David & Chris. Respect
@cybersamurai99
@cybersamurai99 2 жыл бұрын
its double equal == as normally in computer language one equal = generally sets something to be. When you write == you are checking if something matches. I am sure the majority of people would know this but I am just throwing my 2 cents out there :)
@gjkrisa
@gjkrisa 2 жыл бұрын
Oddly this came out when I was searching to see why dsl connection is slow or drops. I’m pretty sure it’s upload hogging the bandwidth but I would like to make a graph as to what going up slows how much going down. There is a point that I can see upload device stays on network and continue upload but everyone else will show no internet so may drop its self from the network like windows will do sometimes
@nonlinearsound-001
@nonlinearsound-001 2 жыл бұрын
I see a pattern here that I could put into software maybe .. hmm .. client sends request, empty ack from server and time to wait until first application data and alike conversations point to performance problems of API endpoints? Could be a nice performance test suite.. :)
@lucaspascual5956
@lucaspascual5956 2 жыл бұрын
Pure gold as always.
@adnaneabid7274
@adnaneabid7274 Жыл бұрын
I think the double equal or === to compare the type or the value, like in JS maybe.
@H3LLB0Y2403
@H3LLB0Y2403 Жыл бұрын
Now, did that episode on the slow network already happen? I'd be very interested :D
@konstantinosprotopapas588
@konstantinosprotopapas588 2 жыл бұрын
I DEFINITELY want to see war stories from Chris Greer.
@terexkiller3847
@terexkiller3847 2 жыл бұрын
Thanks, I love your content. Keep it up
@rationalbushcraft
@rationalbushcraft 2 жыл бұрын
Chris what I would like to know is do you use a tap or do you just mirror a port on the switch. If you use a tap what brand/model do you recomend?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
The answer is yes. Both. If I have a tap, that is my first option. Here is one that I use that doesn't break the bank. amzn.to/3uJYTc0 - Otherwise I use Profitap taps for the higher speeds, just because they have aggregation taps and more features (deduplication, etc). Otherwise I just use a span port when I am doing remote work or if I don't have access to a tap. Spans are fine as long as I watch how much traffic I am sending over to the monitor port.
@rationalbushcraft
@rationalbushcraft 2 жыл бұрын
@@ChrisGreer thanks for that. Nearly 20 years ago I took Laura Chapels class. But in the small to medium market I’m in I didn’t have a lot of opportunity to refine those skills. But every now and then what little I know comes in handy. Thanks for doing these as I really enjoy this packet level stuff.
@dinohunter7176
@dinohunter7176 Жыл бұрын
== is like a standard in programming to check if values match on value if used just one = then mean assigna valuea to that variable, not sure if possible in Wireshark
@nepsky
@nepsky 2 жыл бұрын
What are the best filters to find the Network latency ? Please advise!
@Sycophantichallenger
@Sycophantichallenger 2 жыл бұрын
Can't wait for the next in the series. As the "computer guy" at a retail store with really old crap infrastructure I could really use some pointers with narrowing down what is or is not happening that is impacting the network performance.
@sheepd0gonwatch215
@sheepd0gonwatch215 2 жыл бұрын
This is excellent information. I would like to know how you pull your captures apart from the $4.5K device. Do you ever use port mapping on a switch or do you always use some sort of TAP. I work in a lot of smaller companies that don't have large IT budgets but with CMMC/NIST requirements we are trying to find cost effective and easy to use packet capture equipment/software or solutions.War stories would be great!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hello @Sheepd0g - actually in my consulting practice I don't get to use the IOTA very much since so many of my clients are remote. So I use a span port on a switch pretty often. If that is not available, I look at the virtual network to figure out what vTap or vSPAN options are available, or as a last resort, do dumpcap on the end device. But that is only if I have no other way of getting the data.
@sheepd0gonwatch215
@sheepd0gonwatch215 2 жыл бұрын
@@ChrisGreer Thanks for the quick response. Do you see any drawbacks to using a mirrored port on a switch? I work mostly with HP Aruba switches and sometimes Cisco.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
@@sheepd0gonwatch215 Yes there are - it is easy to over-provision a SPAN or mirrored port. Keep in mind that each interface is full duplex (for example 1Gbps in, 1Gpbs out, for an aggregate of 2Gbps potential load.) The mirror will only be 1Gbps out - or whatever the interface speed is. So be careful not to send too many ports over to the mirror because you can hit that ceiling faster than you think, esp in traffic bursts. Also - SPANs and mirrors don't always preserve the original inter-packet timing very well. It often depends on the load, but the true traffic stream could look really different than the one sent out the mirror, even being several milliseconds off. This is not always a huge deal, but it is something I keep in mind when using a SPAN. For most low-throughput environments, mirrors will be enough, but it's good to know the downsides. Rule of thumb: Tap when possible, SPAN/Mirror when not, after exhausting all other options, capture on the endpoints.
@sheepd0gonwatch215
@sheepd0gonwatch215 2 жыл бұрын
@@ChrisGreer thanks again Chris
Is this an attack? Wireshark Packet analysis // SYN Attack
40:04
David Bombal
Рет қаралды 63 М.
How TCP really works: MTU vs MSS
1:07:02
David Bombal
Рет қаралды 156 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 157 МЛН
This Game Is Wild...
00:19
MrBeast
Рет қаралды 126 МЛН
Players vs Pitch 🤯
00:26
LE FOOT EN VIDÉO
Рет қаралды 130 МЛН
Perfect Pitch Challenge? Easy! 🎤😎| Free Fire Official
00:13
Garena Free Fire Global
Рет қаралды 96 МЛН
How TCP really works // Three-way handshake // TCP/IP Deep Dive
1:01:10
Top 10 Real World Wireshark Filters you need to know
50:09
David Bombal
Рет қаралды 115 М.
TCP/IP for Programmers
3:03:31
Eli the Computer Guy
Рет қаралды 226 М.
How to Troubleshoot Slowness Issues in Network Through Wireshark | Learn Wireshark
1:15:50
Skilled Inspirational Academy(www.sianets.com)
Рет қаралды 16 М.
Top 5 Wireshark tricks to troubleshoot SLOW networks
43:00
David Bombal
Рет қаралды 81 М.
TCP Fundamentals Part 1 // TCP/IP Explained with Wireshark
1:17:24
Chris Greer
Рет қаралды 447 М.
Hacker hunting with Wireshark (even if SSL encrypted!)
1:07:16
David Bombal
Рет қаралды 266 М.
Houdini Algorithmic Live #103 - Freeform Curved Folding
3:50:48
Junichiro Horikawa
Рет қаралды 613 М.
TLS Handshake Deep Dive and decryption with Wireshark
1:05:40
David Bombal
Рет қаралды 285 М.
Decrypting TLS, HTTP/2 and QUIC with Wireshark
28:00
David Bombal
Рет қаралды 108 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 157 МЛН