It’s easy enough to install Wireshark and begin capturing
packets off the wire—or from the air. But how do you
interpret those packets once you’ve captured them? And
how can those packets help you to better understand
what’s going on under the hood of your network?
Practical Packet Analysis shows how to use Wireshark
to capture and then analyze packets as you take an in-
depth look at real-world packet analysis and network
troubleshooting. The way the pros do it.
Wireshark (derived from the Ethereal project), has
become the world’s most popular network sniffing appli-
cation. But while Wireshark comes with documentation,
there’s not a whole lot of information to show you how
to use it in real-world scenarios. Practical Packet Analysis
shows you how to:
• Use packet analysis to tackle common network
problems, such as loss of connectivity, slow networks,
malware infections, and more
• Build customized capture and display filters
• Tap into live network communication
www.nostarch.com
“ I L AY F L AT .”
This book uses RepKover —a durable binding that won’t snap shut.
Printed on recycled paper
TH E F I N E S T I N G E E K E NT E RTA I N M E NT
™
SHELVE IN:
NETWORKING/SECURITY
$39.95 ($49.95 CDN)
®
D O N ’ T J U S T S T A R E
A T C A P T U R E D
P A C K E T S .
A N A L Y Z E T H E M .
D O N ’ T J U S T S T A R E
A T C A P T U R E D
P A C K E T S .
A N A L Y Z E T H E M .
• Graph traffic patterns to visualize the data flowing
across your network
• Use advanced Wireshark features to understand
confusing packets
• Build statistics and reports to help you better explain
technical network information to non-technical users
Because net-centric computing requires a deep under-
standing of network communication at the packet level,
Practical Packet Analysis is a must have for any network
technician, administrator, or engineer troubleshooting
network problems of any kind.
A B O U T T H E A U T H O R
Chris Sanders is the network administrator for the
Graves County Schools in Kentucky, where he
manages more than 1,800 workstations, 20 servers,
and a user base of nearly 5,000. His website,
ChrisSanders.org, offers tutorials, guides, and
technical commentary, including the very popular
Packet School 101. He is also a staff writer for
WindowsNetworking.com and WindowsDevCenter.com.
He uses Wireshark for packet analysis almost daily.
T E C H N I C A L R E V I E W B Y G E R A L D C O M B S , C R E A T O R O F W I R E S H A R K
T E C H N I C A L R E V I E W B Y G E R A L D C O M B S , C R E A T O R O F W I R E S H A R K
Download the capture files
used in this book from
www.nostarch.com/packet.htm
PR AC T IC A L
PACKE T A N A LYSI S
PR AC T IC A L
PACKE T A N A LYSI S
U S I N G W I R E S H A R K T O S O L V E R E A L - W O R L D
N E T W O R K P R O B L E M S
C H R I S S A N D E R S
®
P R A C T I C A L PA C K E T A N A LY S I S
P R A C T I C A L PA C K E T A N A LY S I S
S A N D E R S