When a network isn't behaving the way it should, Wireshark is one of the most useful tools you can have.
Wireshark is a free, open-source network protocol analyzer. It captures network traffic and lets you inspect individual packets instead of relying on what an application, operating system, or network device says is happening. Wireshark
A capture can show source and destination IP addresses, protocols, ports, TCP conversations, DNS requests and responses, DHCP traffic, retransmissions, connection attempts, and hundreds of other protocol details.
That makes Wireshark useful for troubleshooting things such as:
dns
arp
icmp
tcp.port == 443
ip.addr == 192.168.1.10
Wireshark can analyze traffic captured live or open previously recorded PCAP/PCAPNG files. It runs on Windows, Linux, macOS and several other platforms. Wireshark
One important distinction: Wireshark isn't an intrusion-detection system and it doesn't automatically tell you what's wrong. It shows you the packets. Understanding protocols and normal network behavior is what turns those packets into useful information. Wireshark
That's also why Wireshark is such a useful learning tool. Instead of reading that a DNS query happens or that TCP uses a three-way handshake, you can capture the traffic and watch it happen packet by packet.
Wireshark official website
Wireshark is a free, open-source network protocol analyzer. It captures network traffic and lets you inspect individual packets instead of relying on what an application, operating system, or network device says is happening. Wireshark
A capture can show source and destination IP addresses, protocols, ports, TCP conversations, DNS requests and responses, DHCP traffic, retransmissions, connection attempts, and hundreds of other protocol details.
That makes Wireshark useful for troubleshooting things such as:
- A computer that can't reach a server
- DNS requests that aren't getting responses
- TCP connections that repeatedly reset
- DHCP problems
- Unexpected devices communicating on a network
- VoIP troubleshooting
- Investigating suspicious network traffic
dns
arp
icmp
tcp.port == 443
ip.addr == 192.168.1.10
Wireshark can analyze traffic captured live or open previously recorded PCAP/PCAPNG files. It runs on Windows, Linux, macOS and several other platforms. Wireshark
One important distinction: Wireshark isn't an intrusion-detection system and it doesn't automatically tell you what's wrong. It shows you the packets. Understanding protocols and normal network behavior is what turns those packets into useful information. Wireshark
That's also why Wireshark is such a useful learning tool. Instead of reading that a DNS query happens or that TCP uses a three-way handshake, you can capture the traffic and watch it happen packet by packet.
Wireshark official website