WP-201 Advanced Network Analysis and Troubleshooting ("Packets Never Lie")
Duration
Public Class Duration: 3 Days (prerequisite of WP-200 STRONGLY recommended)
Web-Delivered Class Duration: 4 half days (9:30 AM PT - 12:00 PM PT M-TH)
Prerequisite: WP-200 strongly recommended
Overview and Method
This course dives deeper into protocol analysis, particularly a more thorough understanding of TCP/IP and related protocol variants, both benevolent and nefarious. It builds on the troubleshooting concepts in WP-200 to include long-term statistics gathering, monitoring, and general network health. The in-class activities are a bit more advanced, often combining concepts in more complex scenarios for students to decipher. Successful graduates from this class will be ready to immediately apply skills in real-world environments
- Introduction and Overview
- Introductions and logistics
- Class organization
- Special slides and notations
- Philosophy
- The Internet Protocol (IP) In-Depth
- Overview of
- The IP header and its fields
- IP Type of Service and Differentiated Services
- Using the IP ID to assess remote load
- IP Fragmentation Services
- IP Options
- ARP
- Important ARP facts
- Expected ARP behavior
- APR Types
- ARP security
- UDP and TCP Conversations
- Review of the Transport Layer
- Reliable vs. unreliable communications
- Overview of UDP application layer protocols
- ICMP
- Examples of ICMP messages
- The ICMP header
- ICMP message types
- DHCP
- Basic DHCP operations: DORA
- Other DHCP messages
- Problems with DHCP
- Analyzing DHCP
- Troubleshooting DHCP
- DNS
- DNS organization
- DNS in the Peek analyzer
- DNS packet structure and the DNS header
- Troubleshooting DNS
- IGMP and Multicasts
- Layer 2 multicast groups
- The IGMP header
- IGMP in the Peek analyzer
- SNMP and Rmon
- The SNMP MIB
- SNMP packets in the Peek analyzer
- What is RMON?
- SNMP troubleshooting techniques
- IP Security
- IP header review
- Security-related IP header fields
- Types of exploits
- Packet Biathlon – OmniPeek*
- This intensive hands-on lab will allow students to use the OmniPeek Product Family focusing on analysis situations. The course is comprised of a series of in-depth, instructor lead scenarios and trace files that effect an enterprise operation.
* only available via public or onsite