Wireshark/ICMPv6 Echo
Appearance
Wireshark is a free and open source packet analyzer used for network troubleshooting and analysis. These activities will show you how to use Wireshark to capture and analyze Internet Control Message Protocol Version 6 (ICMPv6) Echo traffic.
Readings
[edit | edit source]Preparation
[edit | edit source]To prepare for this activity:
- Start Windows.
- Log in if necessary.
- Install Wireshark.
Activity 1 - Capture ICMPv6 Echo Traffic
[edit | edit source]To capture ICMPv6 Echo traffic:
- Start a Wireshark capture.
- Use ping 2001:4860:4860::8888 to ping one of Google's public IPv6 DNS servers.
- Stop the Wireshark capture.
Activity 2 - Analyze ICMPv6 Echo Request Traffic
[edit | edit source]To analyze ICMPv6 Echo Request traffic:
- Observe the traffic captured in the top Wireshark packet list pane. Look for traffic with ICMPv6 listed as the protocol. To view only ICMPv6 traffic, type icmpv6 (lower case) in the Filter box and press Enter.
- Select the first ICMPv6 packet, labeled Echo (ping) request.
- Observe the packet details in the middle Wireshark packet details pane. Notice that it is an Ethernet II / Internet Protocol Version 6 / Internet Control Message Protocol v6 frame. Note if you are using an IPv6 tunnel, your IPv6 packet may be encapsulated inside an IPv4 or UDP packet.
- Expand Internet Control Message Protocol v6 to view ICMPv6 details.
- Observe the Type. Notice that the type is Echo (ping) request (128).
- Select Data in the middle Wireshark packet details pane to highlight the data portion of the frame.
- Observe the packet contents in the bottom Wireshark packet bytes pane. Notice that Windows sends an alphabet sequence during ping requests.
Activity 3 - Analyze ICMPv6 Echo Reply Traffic
[edit | edit source]To analyze ICMPv6 Echo Reply traffic:
- In the top Wireshark packet list pane, select the second ICMP packet, labeled Echo (ping) reply.
- Observe the packet details in the middle Wireshark packet details pane. Notice that it is an Ethernet II / Internet Protocol Version 6 / Internet Control Message Protocol v6 frame. Again, if you are using an IPv6 tunnel, your IPv6 packet may be encapsulated inside an IPv4 or UDP packet.
- Expand Internet Control Message Protocol v6 to view ICMPv6 details.
- Observe the Type. Notice that the type is Echo (ping) reply (129).
- Select Data in the middle Wireshark packet details pane to highlight the data portion of the frame.
- Observe the packet contents in the bottom Wireshark packet bytes pane. Notice that the reply echoes the request sequence.
- Close Wireshark to complete this activity. Quit without Saving to discard the captured traffic.