This document discusses Wireshark's expert system for network analysis. It explains that the expert system can help understand error, warning, and note events seen in network traffic. Specific event types are covered like bad checksums, unknown dissectors, and TCP sequence/acknowledgment issues. The document encourages using the expert system for initial evaluation of network issues and provides contact information for the author to learn more.
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Network Analysis Using Wireshark Chapter 08 the expert system
1. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 1
Network analysis Using Wireshark
Lesson 8:
The Expert System
2. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 2
• By the end of this lesson, the participant will be able to:
▫ Understand Wireshark Expert System
▫ Understand events and severities
Lesson Objectives
3. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 3
yoram@ndi-com.com
For More lectures, Courses & Keynote Speaking
Contact Me to:
4. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 4
The Expert Info window and how to use it
for network troubleshooting
Error events and understanding them
Warnings events and understanding them
Notes events and understanding them
Case studies
Chapter Content
“Try not to become a man of success.
Rather become a man of value.“
Albert Einstein
5. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 5
The Expert Info Window
6. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 6
The Expert Infos window and how to use
it for network troubleshooting
Error events and understanding them
Warnings events and understanding them
Notes events and understanding them
Case studies
Chapter Content
"If you really look closely, most
overnight successes took a long time.“
Steve Jobs
7. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 7
Error Events:
Bad checksum, Malformed packet
Erorrs: Errors
in Layers 1-7
8. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 8
The Expert Infos window and how to use
it for network troubleshooting
Error events and understanding them
Warnings events and understanding them
Notes events and understanding them
Case studies
Chapter Content
"There are no secrets to success. It is the
result of preparation, hard work, and
learning from failure.“
Colin Powell
9. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 9
Warning Events:
Unknown dissector, Window illegal window shift
10. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 10
Warning Events:
TCP Resets, TCP window issue
11. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 11
The Expert Infos window and how to use
it for network troubleshooting
Error events and understanding them
Warnings events and understanding them
Notes events and understanding them
Case studies
Chapter Content
"There are no secrets to success. It is
the result of preparation, hard work, and
learning from failure.“
Colin Powell
12. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 12
Note Events:
TCP SEQ/ACK Issues
13. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 13
Summary
• In this lesson we talked about:
▫ The expert system and what is the information to get from it
▫ How to use the expert system for initial evaluation of the network
Thanks for your time
Yoram Orzach
yoram@ndi-com.com
14. Network Analysis Using Wireshark Version 2Network Analysis using Wireshark V.2 yoram@ndi-com.com
Network analysis using Wireshark V2 yoram@ndi-com.comPage 14
yoram@ndi-com.com
For More lectures, Courses & Keynote Speaking
Contact Me to: