Troubleshooting TCP/IP network traffic with Wireshark
Course Description
Course Overview
This two-day training introduces participants to the fundamental principles of network packet analysis using Wireshark—the world's most popular network protocol analyzer. It provides a detailed examination of essential Wireshark features and functionality.
The course begins with an overview of key concepts and the formalism of the ISO/OSI reference model (ITU-T X.200) to facilitate more effective, layer-by-layer troubleshooting, alongside an introduction to the TCP/IP protocol suite. The core portion of the training focuses on methods and best practices for capturing packets and analyzing offline traffic.
The goals of this analysis are:
- identifying and troubleshooting issues related to specific services and protocols
- verifying communication between nodes at each OSI layer
- and proactively detecting and preventing potential problems
Detailed lectures are supported by numerous examples and practical exercises based on sample capture files containing real-world network traffic patterns. Participants should have a basic understanding of modern computer networks.
Learning Objectives
- Develop a solid understanding of fundamental terminology and components of the ISO/OSI reference model and the TCP/IP protocol suite, and apply this knowledge to real-world problem solving.
- Build a strong foundation in analyzing and troubleshooting network packets using Wireshark.
- Understand the capabilities and limitations of Wireshark, including packet capture processes, traffic filtering mechanisms (capture filters vs. display filters), and protocol-specific functions.
- Learn to use Wireshark effectively to identify causes of network performance issues.
- Gain insight into user-level application behavior through network traffic analysis.
Book This Course
- Format: Remote
- Language: EN
- Type: Open, Guaranteed Course
- Duration: 2 days (14 hours)
- Start Date: 19-20.10.2026
Price per participant, excluding tax.
Keywords
- Wireshark
- Network Analysis
- TCP/IP Network Analysis
- TCP/IP Troubleshooting
- Packet Capture Analysis
- Network Performance
- Protocol Analysis
Instructor
The course is led by an instructor with over 15 years of experience in network packet analysis. Since 2017, he has conducted over 50 courses, trainings, and seminars across Europe, North America, South America, Australia, and Asia for companies such as Samsung, Rohde & Schwarz, SGP Singapore, SBS Transit Singapore, and PGNiG Poland. From 2008 to 2016, he held senior engineering roles at Nokia Networks, specializing in network troubleshooting and root cause analysis. He holds a Bachelor of Science degree in Engineering (Telecommunications Systems and Networks) and a Master's degree in Mathematics (Statistics and Data Analysis).
Suggested Schedule
The training is divided into four sessions per day, each lasting approximately 1.5 hours, totaling six hours of instruction daily. Breaks are scheduled between sessions, including a longer lunch break. A sample daily schedule is as follows:
- 09:00 – 10:30 Session I
- 10:30 – 10:45 Coffee Break
- 10:45 – 12:15 Session II
- 12:15 – 13:15 Lunch Break
- 13:15 – 14:45 Session III
- 14:45 – 15:00 Coffee Break
- 15:00 – 16:00 Session IV
Target Audience
The course is designed for IT students and professionals, customer support engineers, application support engineers, and network engineers who:
- need to develop essential network packet analysis and troubleshooting skills, including diagnosing issues at all OSI layers (e.g., high latency, packet loss, limited bandwidth),
- want to understand practical and effective network analysis techniques.
Course Syllabus
Day 1
TCP/IP Network Fundamentals
1. The ISO/OSI Reference Model: protocols, services, and selected layer operations.
2. Addressing concepts in Ethernet and IP protocols.
Introduction to Wireshark
1. Architecture and processing flow. What can and cannot be seen with Wireshark?
2. Supported protocols and dissectors.
3. Time values.
4. Exercises.
Traffic Capture
1. Tools.
2. Basic capture filters.
3. Automatic stop criteria.
4. Exercises.
Day 2
Traffic Analysis: Basic Preliminary Analysis Tools
1. Analysis checklist.
2. Quantitative analysis: basic pre-defined descriptive statistics and summaries, including Capture Properties, Protocol Hierarchy, Conversations, Endpoints, and Packet Lengths.
3. Visualizing flows.
4. Understanding the Expert System.
5. Exercises.
Traffic Analysis: Filtering
1. Traffic filtering using display filters and stream following.
2. Utilizing features such as name resolution, coloring, marking, time references, and time shifting.
3. Accessing options via the context menu (right-click).
4. Exercises and case studies.
Traffic Analysis: Case Studies
1. IPv4: fragmentation and packet loss.
2. TCP: retransmissions and zero-window conditions.
Prerequisites
Required Knowledge
1. Basic knowledge of modern computer networks, including a fundamental understanding of layered network principles and architecture, such as TCP/IP.
2. Practical familiarity with operating Unix/Linux systems, including:
- Using the terminal
- Understanding directory structure
- Listing files and directories
- Creating and changing directories
- Copying, moving, and deleting files and directories
- Using redirects and pipes
- Managing processes (e.g., displaying suspended processes and background processes)
Minimum Hardware Requirements
- CPU: Modern dual-core processor, 3 GHz, with at least 4 MB cache memory.
- RAM: Minimum 6 GB.
- Disk Space: At least 20 GB of free space on the system partition, plus an additional 20 GB of free space on any partition. This requirement does not include the operating system itself and refers to the space needed prior to installing the additional software listed below.
Software Requirements
1. Operating System: Ubuntu Linux is preferred. The following tools must be installed from the command line: ip, iperf, and ipcalc.
2. Wireshark: Install the latest stable version available at: https://www.wireshark.org/download.html.
3. FTP Client: Any chosen FTP client.
All applications should be installed in their latest stable versions.
Copyright ©2026 Wojciech Wójciak. All rights reserved.
This document is protected by copyright laws. All copyrights and intellectual property rights pertaining to this documentation are the exclusive property of the author, who holds the rights to copy, modify, translate, adapt, or create derivatives, including any improvements or enhancements. The author has the exclusive right to copy, distribute, modify, develop, license, sublicense, sell, transfer, and convey this material. No part of this document may be reproduced, stored in a retrieval system, adapted, or publicly distributed or disclosed to any third party in any form or by any means without prior written consent from the owner.

No budget? Get funding!
A program that allows you to easily and quickly obtain funds for individual participants' training.

Why choose a guaranteed course?
- Guaranteed delivery — the course takes place regardless of the number of participants.
- Knowledge exchange and networking with professionals from various industries.
- Interactive, live-led sessions — not just theory, but also exercises and discussions.
- Flexible online format — join from anywhere.
Need Help?
Reach out to learn more about our team and the kinds of tailored solutions we can offer your organization.
Get in Touchwroclaw@nobleprog.pl or +48 (22) 103 3718