Aug 18

Some while back one of my US based colleagues passed on some advice about checking out some details on how to get the best out of Wireshark

For anyone interested in getting their feet wet using Wireshark the network protocol analyzer.  This knowledge can be useful to have when dealing with network anomalies.

www.chappellseminars.com/s-wireshark101.html

Download the latest 1.2.1

As you may or may not know this was originally called Ethereal, and then morphed in to Wireshark, and has recently had quite a number of improvements and has moved from ver. 0.9 to now 1.2 plus in the last few months. There has been quite a number of additions including the ability to graph throughput etc from within the tool, as well as it now supporting GeoIP DB’s so that you can carry out extensive mapping of where the packets are going to or coming from.

http://wiki.wireshark.org/HowToUseGeoIP

Running Windows 7?

If you are running Windows 7 – then do be aware that the WinPcap driver (the component that does the sniffing) will fail to install by default – but if you modify the executable to run in Vista SP1 compatability mode then all should be fine – as detailed below:

I’ve just downloaded WinPcap 4.1 beta5 from here: WinPcap, the Packet Capture and Network Monitoring Library for Windows Set the compatibility mode to Windows Vista (right click on the installer executable then select Properties; on the Compatibility tab, check "Run this program in compatibility mode for", select Windows Vista SP1 from the dropdown list, then finally click OK =)) and it will install as it should.
For me it worked flawlessly so far.

Further reading

I then followed this up a bit further and noted that after a recent Sharkfest event there were a number of presentations made by a chap called Ray Tompkins (CEO of Gearbit) and these are available at:

At Sharkfest 2009 gearbit presented 3 sessions::
Finding the Latency:
How Protocols Work:

Wireshark Charts & IO Graphs:
OSTU – Wireshark IO Graph for Response Time Analysis:
Understanding the Need for Protocol Analysis: HYPERLINK
OSTU – Wireshark Case Study: Benchmark Test
OSTU – Wireshark TCP Stream Graphs
OSTU – Wireshark Capture Filters
OSTU – Wireshark Display Filters
OSTU – Identifying Zero Window with Wireshark

If you do find that you have to dig in on a Customers Site to start doing some serious troubleshooting around Networks then I would seriously recommend the first two presentations in PDF format as they do appear to explain things in a very simple and matter of fact way.

Wireless Issues:

Now this should in no way be any sort of substitute for a proper Wireless Survey, but when you find that you are up against some issues then try using inSSIDer as a very good starting point? And it works on Windows 7 straight out of the box ;-)

image

  • Share/Bookmark

written by dcaddick

2 Pings to “I have been chasing Network issues lately and have come across these very useful *FREE* Tools that both work under Windows 7”

  1. I have been chasing Network issues lately and have come across these very useful *FREE* Tools that both work under Windows 7 | networking-the.info Says:

    [...] Read more:  I have been chasing Network issues lately and have come across these very useful *FREE* Tools that b… [...]

  2. links for 2009-08-19 | benway.net Says:

    [...] I have been chasing Network issues lately and have come across these very useful *FREE* Tools that b… wireshark and inSSIDer (tags: network wireless) AKPC_IDS += "861,"; [...]


20 Responses to “I have been chasing Network issues lately and have come across these very useful *FREE* Tools that both work under Windows 7”

  1. 1. Bunker Says:

    Very interesting and amusing subject. I read with great pleasure.

  2. 2. Cornelius Says:

    Valuable thoughts and advices. I read your topic with great interest.

  3. 3. Swingdown Bike Rack Says:

    I had wanted to learn more about this. Thanks for the info!

  4. 4. Spider Says:

    It is surprising but true. Your life is expensive. At least, at its auction it could sell for good money..

  5. 5. Maggy Says:

    Thank you, very interesting article..

  6. 6. Mackeran Says:

    Thank you! You often write very interesting articles. You improved my mood.

  7. 7. John Says:

    Interesting. We are waiting for new messages on the same topic:).

  8. 8. Ventego Says:

    I read a few topics. I respect your work and added blog to favorites.

  9. 9. Javier Says:

    Great site you have – are you having fun with it? Keep up the good work and good luck with your site!

  10. 10. Alex Says:

    Fascinating. We would have to hear the views of experts on this subject:).

  11. 11. Suzan Says:

    The theme of your pretty complicated for a beginner..

  12. 12. Malcom Says:

    The author, and you do not accidentally from Moscow?.

  13. 13. Alex Says:

    Your blog is familiar in the ICQ link threw. It turned out that not in vain. Now I will read regularly.

  14. 14. Julia Says:

    excellent example of standing material. Fortunately, the author simply genius.

  15. 15. Anonyme Says:

    Material for five and a plus. But there are negative! My internet speed 56kb/sek. Page loaded about 40 seconds..

  16. 16. Webmaster Says:

    Fully agree with you, about a week ago, wrote about etozhe on your blog!.

  17. 17. X-man Says:

    Yes, all clear Spasibochki for the post..

  18. 18. X-man Says:

    Read, of course, far from my topic. But still, you can cooperate with you. How do you treat yourself to a trust management?.

  19. 19. Joe Says:

    I have found Inssider not to show any higher singal than -50 when used with Windows 7.

  20. 20. ???? ??????? Says:

    ???… :) ?? ?? ????? ??? ??? ??? ????? ? ?????? ?????? :)

Leave a Reply