Wireshark/Ethernet
Appearance
Wireshark is a free and open source packet analyzer used for network troubleshooting and analysis. These activities will show you how to use Wireshark to capture and analyze Ethernet traffic.
Readings
[edit | edit source]Preparation
[edit | edit source]To prepare for this activity:
- Start Windows.
- Log in if necessary.
- Install Wireshark.
Activity 1 - Capture Ethernet Traffic
[edit | edit source]To capture Ethernet traffic:
- Start a Wireshark capture.
- Use ipconfig to display the default gateway address. Note the Default Gateway displayed.
- Use ping <default gateway address> to ping the default gateway address.
- Stop the Wireshark capture.
Activity 2 - Analyze Ethernet Traffic
[edit | edit source]To analyze Ethernet traffic:
- Observe the traffic captured in the top Wireshark packet list pane. All of the traffic you see is likely to be Ethernet traffic. If you want to specifically identify the traffic generated from the ping command above, look for traffic with ICMP listed as the protocol and Echo (ping) request or Echo (ping) reply in the description.
- Select a packet you want to analyze.
- Observe the packet details in the middle Wireshark packet details pane.
- Select Frame. Notice when you select the frame that the entire frame is highlighted in the bottom packet bytes pane.
- Expand Frame to view frame details.
- Expand Ethernet II to view Ethernet details. Notice the Destination, Source, and Type fields.
- Select the Destination field. Notice when you select the Destination field that the first six bytes of the frame are highlighted in the bottom packet bytes pane. This is the destination MAC address for the Ethernet frame.
- Select the Source field. Notice when you select the Source field that the second six bytes of the frame are highlighted in the bottom packet bytes pane. This is the source MAC address for the Ethernet frame.
- Select the Type field. Notice when you select the Type field that the 13th and 14th bytes of the frame are highlighted in the bottom packet bytes pane. This is the type of packet encapsulated inside the Ethernet frame.
- Select additional Ethernet frames in the top packet list pane and observe frame details in these packets.
Activity 3 - Confirm MAC Addresses in Ethernet Traffic
[edit | edit source]To confirm MAC addresses in Ethernet traffic:
- Use ipconfig /all or Getmac to display your computer's Physical Address.
- Compare your computer's physical address to the Source and Destination fields in the captured traffic. Identify which frames were sent by your computer and which frames were received by your computer.
- Use arp -a to view the ARP cache.
- Locate the default gateway IP address used in the ping command above and note the Physical Address of the default gateway.
- Compare your default gateway's physical address to the Source and Destination fields in the captured traffic. Identify which frames were sent by the default gateway and and which frames were sent to the default gateway.
- Close Wireshark to complete this activity. Quit without Saving to discard the captured traffic.