SlideShare uma empresa Scribd logo
1 de 14
Examining hrPINGv2.39  with  Wireshark  Part 2 Tony Fortunato, Sr Network Specialist Peter Ciuffreda, Network Technician The Technology Firm
hrPING  Options  to review In part 2 we use Wireshark to ensure that the various options work as advertised -l size Send buffer size (ICMP payload size). How may bytes payload should be send? Remember that each packet is of the form: IP header (20 bytes) + ICMP header (8 bytes) + payload. You may  only specify the payload size. Minimum is 0, maximum is 64k-1-20-8, i.e., 65507 bytes. Default  is 64 bytes. -L size Total IP datagram size (ICMP payload size + 28). Same as the above, only that this size here is the size for the total IP datagram. -f Set Don't Fragment flag in packet. Set the &quot;Don't fragment&quot; bit in the IP header of the PING packet. Default is not set. -i TTL Time To Live. Set the &quot;Time To Live&quot; value in the IP header of the PING packet. Default is 255. -v TOS Type Of Service. Set the &quot;Type Of Service&quot; bits in the IP header of the PING packet. Default is 0. -w timeout Timeout in milliseconds to wait for each reply. Maximum timeout to wait for a reply. This is almost only of use if you switch to non-overlapped (i.e., Windows PING like) mode. In overlapped mode, this time only applies when hrPING has stopped sending (because the count was exceeded or because you pressed CTRL-C) and is waiting for missing replies. Default is 2000 milliseconds. -s time Interval in milliseconds between packets. This is the number of milliseconds between sending of two PING packets. hrPING will try to stick to this number very accurately. If sending took a little longer for one packet it will send out the next packet a little earlier. Default is 500 milliseconds. (You can use decimals for a very fine grained interval: -s5.4 will send a packet every 5400 microseconds, on average!) -I  Set ICMP id field to <id> Set the &quot;Identification&quot; IP header field to the value specified. It is possible that Windows erases or overwrites this field when sending the packet -o  Don't do overlapped send/receive. Use Windows PING like synchronous sending of one packet, waiting for the reply and so on. Off by default.
Wireshark Setup ,[object Object]
hrPING PING Signature ,[object Object],[object Object],[object Object],[object Object],est omnis divisa in partes tres, quarum unam incolunt Bel hrping
hrPing  -l size option ,[object Object],[object Object],[object Object]
hrPing  -L size option ,[object Object],[object Object]
hrPing  -f option ,[object Object],[object Object]
hrPing  --i TTL ,[object Object],[object Object]
hrPing -v TOS  ,[object Object],[object Object],[object Object],[object Object]
hrPing -v TOS … continued ,[object Object],[object Object]
hrPING Timeout and Interval Options (-w, -o) ,[object Object],[object Object]
hrPING ICMP ID (-I) ,[object Object],[object Object],[object Object],[object Object]
hrPING Examination Tony Fortunato, Sr Network Specialist Peter Ciuffreda, Network Technician The Technology Firm Thank you
[object Object],[object Object],LoveMyTool.com – Community for Network Tools

Mais conteúdo relacionado

Mais de Denny K

Mais de Denny K (20)

3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
3/12/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
3:5:2024 - Third Noble Truth • Mindfulness Meditation and Dharma Talk with Ve...
 
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/27/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
2/20/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
2/13/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
2/6/2023 - Second Noble Truth • Mindfulness Meditation and Dharma Talk with V...
 
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/30/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
1/23/2024「同心共善」善心法師網上禪修班 (粵語) ..........
 
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
1/16/2024「同心共善」善心法師網上禪修班 (粵語) ……………………..
 
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
1/9/2024「同心共善」善心法師網上禪修班 (粵語) ………………………..
 
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
1/2/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
 
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/27/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
 
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
12/20/2023「同心共善」善心法師網上禪修班 (粵語) …………………..
 
12/13/2023「同心共善」善心法師網上禪修班 (粵語)……………………..
12/13/2023「同心共善」善心法師網上禪修班 (粵語)……………………..12/13/2023「同心共善」善心法師網上禪修班 (粵語)……………………..
12/13/2023「同心共善」善心法師網上禪修班 (粵語)……………………..
 
12/6/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
12/6/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong12/6/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
12/6/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
 
11/29/2023「同心共善」善心法師網上禪修班 (粵語)
11/29/2023「同心共善」善心法師網上禪修班 (粵語)11/29/2023「同心共善」善心法師網上禪修班 (粵語)
11/29/2023「同心共善」善心法師網上禪修班 (粵語)
 
11/22/2023「同心共善」善心法師網上禪修班 (粵語)
11/22/2023「同心共善」善心法師網上禪修班 (粵語)11/22/2023「同心共善」善心法師網上禪修班 (粵語)
11/22/2023「同心共善」善心法師網上禪修班 (粵語)
 
10/18/2023「同心共善」善心法師網上禪修班 (粵語)
10/18/2023「同心共善」善心法師網上禪修班 (粵語)10/18/2023「同心共善」善心法師網上禪修班 (粵語)
10/18/2023「同心共善」善心法師網上禪修班 (粵語)
 
10/11/2023「同心共善」善心法師網上禪修班 (粵語)
10/11/2023「同心共善」善心法師網上禪修班 (粵語)10/11/2023「同心共善」善心法師網上禪修班 (粵語)
10/11/2023「同心共善」善心法師網上禪修班 (粵語)
 
10/4/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
10/4/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong10/4/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
10/4/2023 - Mindfulness Meditation and Dharma Talk with Venerable De Hong
 

Último

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Último (20)

2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 

OSTU - hrPING QuickStart Part 2 (by Tony Fortunato & Peter Ciuffreda)

  • 1. Examining hrPINGv2.39 with Wireshark Part 2 Tony Fortunato, Sr Network Specialist Peter Ciuffreda, Network Technician The Technology Firm
  • 2. hrPING Options to review In part 2 we use Wireshark to ensure that the various options work as advertised -l size Send buffer size (ICMP payload size). How may bytes payload should be send? Remember that each packet is of the form: IP header (20 bytes) + ICMP header (8 bytes) + payload. You may only specify the payload size. Minimum is 0, maximum is 64k-1-20-8, i.e., 65507 bytes. Default is 64 bytes. -L size Total IP datagram size (ICMP payload size + 28). Same as the above, only that this size here is the size for the total IP datagram. -f Set Don't Fragment flag in packet. Set the &quot;Don't fragment&quot; bit in the IP header of the PING packet. Default is not set. -i TTL Time To Live. Set the &quot;Time To Live&quot; value in the IP header of the PING packet. Default is 255. -v TOS Type Of Service. Set the &quot;Type Of Service&quot; bits in the IP header of the PING packet. Default is 0. -w timeout Timeout in milliseconds to wait for each reply. Maximum timeout to wait for a reply. This is almost only of use if you switch to non-overlapped (i.e., Windows PING like) mode. In overlapped mode, this time only applies when hrPING has stopped sending (because the count was exceeded or because you pressed CTRL-C) and is waiting for missing replies. Default is 2000 milliseconds. -s time Interval in milliseconds between packets. This is the number of milliseconds between sending of two PING packets. hrPING will try to stick to this number very accurately. If sending took a little longer for one packet it will send out the next packet a little earlier. Default is 500 milliseconds. (You can use decimals for a very fine grained interval: -s5.4 will send a packet every 5400 microseconds, on average!) -I Set ICMP id field to <id> Set the &quot;Identification&quot; IP header field to the value specified. It is possible that Windows erases or overwrites this field when sending the packet -o Don't do overlapped send/receive. Use Windows PING like synchronous sending of one packet, waiting for the reply and so on. Off by default.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.
  • 13. hrPING Examination Tony Fortunato, Sr Network Specialist Peter Ciuffreda, Network Technician The Technology Firm Thank you
  • 14.

Notas do Editor

  1. Hello, It’s Tony Fortunato And Peter Ciuffreda from the Technology Firm In this session we are going to Examine hrPing in a bit more detail Enjoy
  2. Why are we working on hrPing again? In this presentation I want to use Wireshark to show if hrPing’s options really work as advertised. I’m confused, why wouldn’t they? Well sometimes either software goes out with a bug, or the supporting documentation isn’t clear. I’m sure you know how it feels when you put a lot of time in writing something and the audience misunderstands. Trust me Tony, I know the feeling.
  3. I guess we better setup Wireshark to capture our ICMP or ping packets. I can’t tell you how many times I see analysts hit the start button and then struggle through various display filters So what do you suggest we do to avoid that? Just a simple protocol filter. Type icmp in the capture filter area
  4. The ping signature was pretty easy to see. Yeah, we basically looked at the Packet Bytes pane and there it was An application signature is something I always try to find to make application identification easier. We also noticed that Microsoft’s ping signature is the alphabet
  5. This option truly controls the ICMP data payload size We have seen many applications that the size values are the IP payload size, not the ICMP payload. Be careful, some routers or firewalls may not let IP/ICMP fragments through.
  6. In this case, the –L option controls the size of the IP payload So then 5,000 Bytes, isn’t really 5,000 Bytes is it? Nope
  7. OK, I can see the packet isn’t fragmented the first example, then is fragmented in the second. What’s the big deal? Sometimes when network devices can’t transmit the entire packet, they fragment the packet. But only if fragmentation is allowed. I get it, so if you want to send a specific packet size and make sure it doesn’t get fragmented you can test for it, right? Yup
  8. Now this one I understand. We can change the Time to live to see if the packet is traversing more routers or hops, right? Exactly. I also want to see if the ping works and then fails. What does that tell you If there are multiple routes, one router could be flapping causing an extra hop
  9. Ok, so something finally failed. The –v option doesn’t work, right? Actually, the programmer had enough foresight or experience to check if the proper registry setting is in place to make this option work.
  10. I see, now that you modified your registry, it works. Would you consider this a problem? Not really. Since the programmer pretty well told us exactly what to change, I think this is one of those options you need to pay attention to if you have an issue.
  11. Why would you ever NOT want to count a packet? Sometimes due to excessive delay, ARP resolution, or congestion, you may want to ignore that first packet. So if the remaining ones come through ok, you would be fine with that? absolutely
  12. Ok, Tony you have to explain why I would want to specify an ICMP ID number? The only scenario I can think of using this option is if there s a considerable amount of ICMP traffic on a link and you want to quickly pick out your packets.
  13. Tony: Hope you enjoyed this tip Peter: Have a good day folks, bye for now.