Re: [Wireshark-users] Beginner

2007-07-12 Thread Laura Chappell
reconnaissance. Free to all. I agree with the need to understand the protocols! I co-authored “Guide to TCP/IP” with Ed Tittel – not sure where it is sold – it’s used as a college textbook – check Amazon I guess. Laura Chappell Founder, Wireshark University Sr. Protocol/Security Analyst

Re: [Wireshark-users] Wireshark conference

2007-06-30 Thread Laura Chappell
I'd go! Sounds like a great idea, Gerald! Laura Chappell Founder, Wireshark University Sr. Protocol/Security Analyst, Protocol Analysis Institute ** This message is intended only for the use of the addressee an

Re: [Wireshark-users] Limit _certain_ packets to 67 bytes?

2007-06-28 Thread Laura Chappell
no DNS/DHCP. Then merge the two trace files. just an idea. Laura Chappell Founder, Wireshark University Sr. Protocol/Security Analyst, Protocol Analysis Institute ** This message is intended only for the use of

Re: [Wireshark-users] Limit _certain_ packets to 67 bytes?

2007-06-28 Thread Laura Chappell
Yes, in the Capture Options window select "Limit each packet to bytes" and fill out the number of bytes you want. Laura Chappell Founder, Wireshark University Sr. Protocol/Security Analyst, Protocol Analysis

Re: [Wireshark-users] TCP Window Size

2007-06-13 Thread Laura Chappell
s until the Window Update is received. It's a nice trace - it was a terrible download - over a 32 second delay because of the client TCP buffer space being overloaded. Ouch. Laura Chappell Founder, Wireshark University Sr. Protocol/Security Analyst, Protocol Analysis Institute ww

Re: [Wireshark-users] Question on Internet Performance Troubleshooting

2007-03-02 Thread Laura Chappell
Jim, If you can capture on both sides of the firewall with two time synced WS systems then you can merge the trace files and note the delay at the firewall. 10% is really high - now it may be that there is packet loss somewhere upstream (closer to the HTTP server) and it's not your firewall's f

Re: [Wireshark-users] OUI Look Up Tool on Wireshark site?

2007-01-21 Thread Laura Chappell
Keith, You could go straight to the IEEE to read the list (http://standards.ieee.org/regauth/oui/oui.txt) or do a lookup online (http://standards.ieee.org/regauth/oui/index.shtml). Hope that helps. (I couldn't access the link you provided, so I couldn't see how the lookup tool worked - di

Re: [Wireshark-users] Inter packet arrive time graph

2007-01-21 Thread Laura Chappell
You can make a really nice graph of the MIN, MAX and AVG "frame.time_delta". Statistics > IO Graph > Y Axis (set to Advanced). Graph 1 - Black:AVG frame.time_delta Graph 2 - Red: MIN frame.time_delta Graph 3 - Green:

Re: [Wireshark-users] Help on tcpdump or dumpcap

2007-01-18 Thread Laura Chappell
Yes - that's the idea. Even if you capture some really large trace files that take too long to load, you can use editcap to split the file into smaller pieces. Type editcap -h for more information, but the syntax is. Editcap -c 10 Where is the name of your really large capture file and

Re: [Wireshark-users] Duplicate Packet ID

2007-01-16 Thread Laura Chappell
Reza... Here is an idea, but it will only dump the duplicate packet (not the original) and it is set for TCP only. No UDP equivalent that I know of. tshark -R tcp.analysis.retransmission -w Use the capital 'R' to indicate you are using display filter syntax. The retransmissions are def