Lab Instructions
- Attendance: Checked at the beginning of lab class
- Login Credentials:
- Username:
student - Password:
Siit@1992
- Username:
- Exercise Marker: ✔ sign identifies your exercises
- Some exercises require TA's signature
- Completion: Show Lab Sheet to TA when finished
- Quiz: 10-minute quiz at the end of class
- Submission: Last page must be submitted to TA
Lab Overview
Analogy: Think of packet capture like having a surveillance camera on a highway. You can see every car (packet) that passes, where it came from, where it's going, and what it's carrying. This helps you understand traffic patterns and spot any unusual activity.
Purpose: As a network engineer, you need to see what's happening with each packet in your network traffic flow. Packet capture allows you to:
- Investigate high bandwidth usage
- Monitor network for suspicious traffic
- Analyze individual packets as they flow across the network
Tools Used: tcpdump and wireshark (known as packet sniffers)
Section 1: Using tcpdump to Capture Network Traffic
tcpdump is a command-line tool used to capture packets sent/received via a specific Network Interface Card (NIC).
1.1 Check if tcpdump is Installed
Command:
$ tcpdump -hWhat it does: Displays help information and confirms installation
1.2 View List of Network Interface Cards (NICs)
Command:
$ sudo tcpdump -DExpected Output: List of available NICs (e.g., eth0, eth1, eth2, lo, any)
Analogy: NICs are like different doors in your house. Each door (NIC) can let traffic in and out. You need to choose which door you want to monitor.
1.3 Capture Network Traffic on a NIC
General Syntax:
$ sudo tcpdump -i NICname -w FileNameStep-by-Step Activity:
-
Generate Network Traffic:
- Open a web browser
- Navigate to a website (e.g.,
www.amazon.com)
-
Start Capturing:
$ sudo tcpdump -i eth0 -w traff1.dump-i eth0: Interface to monitor (eth0)-w traff1.dump: Write output to file
-
Stop Capturing:
- Wait 5 seconds
- Press
CTRL-Cto stop and save
Note: The file is saved in binary format, not human-readable text.
1.4 Read Captured Traffic File
General Syntax:
$ sudo tcpdump -r FileNameExample:
$ sudo tcpdump -r traff1.dumpIf Permission Denied Error Occurs:
$ sudo apparmor_parser -R /etc/apparmor.d/usr.sbin.tcpdumpThen retry the read command.
1.5 Capture Specific Number of Packets
General Syntax:
$ sudo tcpdump -i NICname -c NumberPacket -w FileNameStep-by-Step Activity:
-
Generate Traffic:
- Open web browser
- Go to website (e.g.,
www.google.com)
-
Capture Only 5 Packets:
$ sudo tcpdump -i eth0 -c 5 -w traff2.dump-c 5: Capture count = 5 packets
-
Read the File:
$ sudo tcpdump -r traff2.dump
1.6 Capture Specific Type of Packets (Filtering)
You can filter packets by:
- IP address
- Protocol type (ICMP, TCP, UDP, etc.)
Example: Capture Only ICMP Packets
Step-by-Step Activity:
-
Generate Mixed Traffic:
- Open web browser and visit a website
- Open terminal and ping a friend's computer:
$ ping IPaddress
-
Capture Only ICMP Packets:
$ sudo tcpdump -i eth0 -c 5 -w traff3.dump icmpicmp: Filter for ICMP protocol only
-
Verify the Capture:
$ sudo tcpdump -r traff3.dump- You should see only ICMP packets captured
Analogy: Filtering is like setting up a specific camera that only records red cars on the highway, ignoring all other vehicles. This helps you focus on what you're looking for.
Section 2: Using wireshark to Capture Network Traffic
Wireshark is an open-source, cross-platform GUI tool for packet capture and analysis.
Features:
- Detailed breakdown of network protocol stack for each packet
- Color-coding based on protocol
- Filter and search functionality
- TCP stream extraction
- Save/import packet captures
- Generate statistics
2.1 Start Wireshark
Command:
$ sudo wiresharkWhat You'll See: Wireshark Graphic User Interface (GUI)
2.2 Select Network Interface
Step-by-Step:
- Click the Capture Interfaces icon (on left-hand side)
- Choose
eth0(or your active NIC) - Click Close button
Why? You must tell Wireshark which "door" (NIC) to monitor for incoming/outgoing traffic.
2.3 Generate Network Traffic
Activity:
- Open web browser
- Navigate to website (e.g.,
www.tu.ac.th)
2.4 Start Packet Capture
Action: Click the Start Capture icon (shark fin/play button)
What You'll See: Real-time list of packets monitored via eth0
2.5 Understanding Wireshark GUI Components
The GUI has 5 major parts:
a) Command Menu
- Top menu bar with File, Edit, View, Go, Capture, Analyze, Statistics, etc.
b) Display Filter
- Text field where you enter commands to show specific packets
- Located below the command menu
c) Packet-Listing Window
- One-line summary for each packet showing:
- Source IP
- Destination IP
- Protocol
- Length (bytes)
- Summary information
d) Packet-Detail Window
- Provides detailed breakdown of selected packet
- Shows protocol layers (Ethernet, IP, TCP/UDP, etc.)
e) Packet-Content Window
- Displays entire packet contents in:
- ASCII format
- Hexadecimal format
Analogy: Think of these windows as different zoom levels on a microscope. The packet-listing is like looking at many cells at once, the packet-detail zooms into one cell's structure, and the packet-content shows you the cell's DNA in raw form.
2.6 Color Coding in Wireshark
Wireshark uses different colors for different packet types.
To View Color Meanings:
- Menu:
View > Coloring Rules
Common Colors:
- Light blue: UDP traffic
- Light green: HTTP traffic
- Black: TCP packets with problems
- Light purple: TCP traffic
- Yellow: ICMP traffic
Section 3: Display Filtering the Network Traffic
Problem: Too much information on screen → hard to find what you need
Solution: Display filters show only packets matching specific criteria
Prerequisites:
- Computer connected to Internet
- Web browser open with these sites visited:
www.tu.ac.thwww.siit.tu.ac.thwww.nectec.or.th
- Wireshark capturing this traffic
3.1 Comparison and Logical Operators
Comparison Operators
| Operator | Meaning |
|---|---|
== | Equal to |
!= | Not equal to |
> | Greater than |
>= | Greater than or equal to |
< | Less than |
<= | Less than or equal to |
Logical Operators
| Operator | Meaning |
|---|---|
&& | Both conditions must be true (AND) |
| | Either condition must be true (OR) |
! | Neither condition is true (NOT) |
3.2 IP Address Filtering
Filter Commands:
| Filter | Meaning |
|---|---|
ip.addr | Show packets from/to this IP address |
ip.src | Show packets sent FROM this source IP |
ip.dst | Show packets sent TO this destination IP |
Example 1: Filter by Source IP
Command:
ip.src==203.131.212.198
Result: Shows only packets sent from IP 203.131.212.198 (www.tu.ac.th)
Example 2: Combine Multiple Conditions
Command:
ip.src==203.131.212.198 || ip.dst==35.197.141.103
Result: Shows packets either:
- FROM
203.131.212.198, OR - TO
35.197.141.103(www.siit.tu.ac.th)
Analogy: IP filtering is like setting up a filter on your email to only show messages from specific senders. You're narrowing down the flood of information to just what matters.
3.3 Protocol Filtering
Filter Commands:
| Filter | Meaning |
|---|---|
arp | Show only ARP packets |
icmp | Show only ICMP packets |
tcp | Show only TCP packets |
udp | Show only UDP packets |
Example: Show Only TCP Packets
Command:
tcp
3.4 Filter by Frame Length
Command:
frame.len < 1000
Meaning: Show only packets with frame length less than 1000 bytes
General Format:
frame.len <operator> <value>
3.5 Filter by Hostname
Command:
http.host == www.tu.ac.th
Result: Shows only packets containing this specific hostname
Section 4: Using Wireshark to Analyze the Ping Procedure
Objective: Capture and analyze the packet exchange when using the ping command
Context: When you ping a new IP address, your computer must first discover the MAC address using ARP (Address Resolution Protocol) before it can send ICMP packets.
4.1 Check ARP Cache
Command:
$ arp -nWhat it does: Displays current ARP cache (IP-to-MAC address mappings)
4.2 Ping New IP Address (Not in Cache)
Step-by-Step Activity:
-
Choose a target IP not in your ARP cache (e.g.,
192.178.18.3) -
Send 5 ping packets:
$ ping -c 5 192.178.18.3-c 5: Count = 5 packets
Expected Output:
- 5 packets transmitted
- 5 packets received
- 0% packet loss
- Round-trip time statistics
4.3 Verify ARP Cache Updated
Command:
$ arp -nWhat You'll See: The IP address 192.178.18.3 and its MAC address now appear in the cache
Analogy: The ARP cache is like your phone's contact list. Once you've looked up someone's number (MAC address) for their name (IP address), you save it so you don't have to look it up again next time.
4.4 Analyze Ping in Wireshark
Filter Command:
arp || icmp
Result: Display only ARP and ICMP packets
📊 What You Should See in Wireshark
The packet sequence will look like this:
Step-by-Step Packet Flow:
-
ARP Request (Broadcast)
- Your computer → All computers in network
- Message: "Who has IP 192.178.18.3? Tell [your IP]"
- Destination MAC:
ff:ff:ff:ff:ff:ff(broadcast)
-
ARP Reply
- Target computer (192.178.18.3) → Your computer
- Message: "I have 192.178.18.3, my MAC is [MAC address]"
- Now your computer knows where to send ICMP packets
-
ICMP Echo Request #1
- Your computer → 192.178.18.3
- "Ping!" (Are you there?)
-
ICMP Echo Reply #1
- 192.178.18.3 → Your computer
- "Pong!" (Yes, I'm here!)
-
Repeat steps 3-4 for packets #2, #3, #4, #5
🔍 Detailed Explanation
a) Why ARP First?
- Your computer doesn't know the MAC address of 192.178.18.3
- Without MAC address, it cannot send the ping (ICMP) packet
- ARP resolves IP address → MAC address
b) Broadcast ARP Request
- Your computer sends an ARP request to all computers on the local network
- Asking: "Who has this IP address?"
c) Target Responds
- The computer with IP 192.178.18.3 replies
- Includes its MAC address in the response
d) Ping Starts Working
- Now your computer can send ICMP packets directly
- 5 ICMP Echo Requests sent
- 5 ICMP Echo Replies received
Analogy: Imagine you're at a party trying to find someone named "Bob" (the IP address). You don't know what Bob looks like (MAC address). So you shout "WHERE'S BOB?" (broadcast ARP). Bob hears and says "I'm Bob, and I'm wearing a red shirt!" (ARP reply with MAC). Now you can walk directly to Bob (send ICMP packets) without shouting again.
Assignments
Assignment 1: Ping to IP Already in ARP Cache
Objective: Understand what happens when pinging a known IP address
Steps:
-
Check ARP Cache:
$ arp -nNote which IP addresses are already cached
-
Ping a Cached IP:
$ ping -c 5 [IP_from_cache] -
Apply Wireshark Filter:
arp || icmp
Question to Answer:
- Are there any ARP packets captured from this ping?
- Why or why not?
Expected Result:
- NO ARP packets should appear
- Only ICMP packets visible
- Why? MAC address already known from cache
Key Learning: When the MAC address is already in the ARP cache, no ARP broadcast is needed. Your computer can immediately send ICMP packets.
Assignment 2: Trace Packets from www.siit.tu.ac.th
Objective: Filter and analyze traffic from a specific website
Steps:
-
Visit Websites:
- Open browser and visit:
www.tu.ac.thwww.siit.tu.ac.thwww.nectec.or.th
- Open browser and visit:
-
Create a Filter:
- Display only packets exchanged with SIIT web server
- Hint: Use
ip.addrorhttp.hostfilters
Possible Solutions:
Option 1: Filter by IP address
ip.addr==35.197.141.103
Option 2: Filter by hostname
http.host == www.siit.tu.ac.th
Option 3: Combine filters for more precision
ip.addr==35.197.141.103 && tcp
What to Explain to TA:
- Which filter you used
- Why this filter works
- What types of packets you see
Assignment 3: Find Who Has Pinged You
Objective: Use Wireshark to identify and analyze incoming pings
Scenario:
- Each student pings 2-4 other computers
- Random number of packets (e.g., 5, 10, 15)
- Random packet length (e.g., 64, 128, 256 bytes)
Your Task:
- Identify who pinged you
- Count how many packets they sent
- Determine the packet length
Steps:
-
Start Wireshark Capture
-
Wait for pings from other students
-
Apply ICMP Filter:
icmp -
Analyze Each ICMP Packet:
- Look at Source IP → Who pinged you
- Count packets with same source IP → Number of pings
- Check Length column → Packet size
-
Record in Table:
| Source IP Address | Number of Pinging Packets | Packet Length |
|---|---|---|
| (Who pinged you) | ||
Advanced Filtering:
To isolate packets from specific source:
icmp && ip.src==192.178.18.5
To see only echo requests (incoming pings):
icmp.type==8
To see only echo replies (your responses):
icmp.type==0
For Online Students:
- Use IMUNES to simulate the traffic
- Create virtual network topology
- Run ping commands between virtual hosts
🔑 Key Concepts Summary
tcpdump vs Wireshark
| Feature | tcpdump | Wireshark |
|---|---|---|
| Interface | Command-line | Graphical (GUI) |
| Platform | Linux/Unix focused | Cross-platform |
| Use Case | Quick captures, scripts | Detailed analysis |
| Real-time display | Limited | Excellent |
| Filtering | Command-line syntax | User-friendly display filters |
| Best for | Remote servers, automation | Desktop analysis, learning |
Important Commands Reference
tcpdump Commands
# List interfaces
sudo tcpdump -D
# Capture on interface
sudo tcpdump -i eth0 -w file.dump
# Capture specific number
sudo tcpdump -i eth0 -c 10 -w file.dump
# Filter by protocol
sudo tcpdump -i eth0 icmp -w file.dump
# Read capture file
sudo tcpdump -r file.dumpWireshark Filters
# IP filters
ip.src==192.168.1.1
ip.dst==192.168.1.1
ip.addr==192.168.1.1
# Protocol filters
tcp
udp
icmp
arp
http
# Combined filters
tcp && ip.src==192.168.1.1
icmp || arp
http.host == www.example.com
# Frame filters
frame.len < 1000
frame.len > 500 && frame.len < 1500
📚 References
- L. Limwiwatkul, ITS352 Lecture/Lab Note, Academic Year 2/2017
- S. Gordon, Networking Lab Manual, 2015
✅ Lab Completion Checklist
- Completed Section 1: tcpdump exercises (1.1-1.6)
- Completed Section 2: Wireshark setup (2.1-2.6)
- Completed Section 3: Display filtering (3.1-3.5)
- Completed Section 4: Ping analysis (4.1-4.4)
- Completed Assignment 1: Ping cached IP
- Completed Assignment 2: Trace SIIT packets
- Completed Assignment 3: Identify incoming pings
- Got TA signatures for all assignments
- Completed 10-minute quiz
- Submitted answer sheet to TA
💡 Pro Tips
-
Always use sudo: Both tcpdump and Wireshark need root privileges to capture packets
-
Understand ARP first: Many networking issues become clear when you understand ARP resolution
-
Use filters effectively: Start with broad filters (like
tcp) then narrow down (liketcp.port==80) -
Follow TCP streams: In Wireshark, right-click a packet → "Follow TCP Stream" to see entire conversation
-
Save your captures: Keep
.pcapfiles for later analysis and learning -
Color coding helps: Learn the Wireshark color scheme to quickly identify packet types
-
Use both tools: tcpdump for quick captures, Wireshark for detailed analysis
🎓 Learning Outcomes
After completing this lab, you should be able to:
- ✅ Use tcpdump to capture network traffic from command line
- ✅ Use Wireshark GUI for packet capture and analysis
- ✅ Apply display filters to isolate specific traffic
- ✅ Understand the relationship between ARP and ICMP
- ✅ Analyze packet-level details of network communication
- ✅ Troubleshoot network issues using packet analysis
- ✅ Identify suspicious or unusual network activity
🔬 Further Exploration
Want to dive deeper? Try these:
- Capture HTTPS traffic: Notice you can't see encrypted content
- Analyze DNS queries: Filter by
dnsto see domain name lookups - Study TCP handshake: Filter
tcp.flags.syn==1to see connection establishment - Export specific packets: Save interesting packets for later study
- Create custom filters: Build complex filters combining multiple conditions
- Use tshark: Command-line version of Wireshark (best of both worlds)
End of Lab Notes