Intro to Wireshark Tutorial // Lesson 4 // Where do we capture network traffic? How?

Поделиться
HTML-код
  • Опубликовано: 14 май 2024
  • Where do we capture network traffic and how? In this lesson we will look into where we should place Wireshark to get the best vantage point in our packet captures. Client side? Server side? or both?
    Please smash the like button to let me know if you think this is good content!
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywireshark
    ▶Getting Started with Nmap - bit.ly/udemynmap
    == Live Wireshark Training ==
    ▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
    == Private Wireshark Training ==
    Let's get in touch - packetpioneer.com/product/pri...
    Chapters in video:
    0:00 Intro
    1:10 Where to place Wireshark
    2:46 Capturing with Taps
    3:46 Capturing with SPAN ports
    4:18 Capturing on the client machine
    5:16 Capturing server side

Комментарии • 49

  • @dopy8418
    @dopy8418 3 года назад +7

    Where can we get a t-shirt like that ?

    • @ChrisGreer
      @ChrisGreer  3 года назад +23

      So crazy you ask... I was literally just thinking... Should I set up my RUclips shirt store so the good packet people can buy a Packet Head shirt?? What do you guys think?

    • @ChrisGreer
      @ChrisGreer  3 года назад +6

      Ok guys - I just got the merch store going - go get that Packet Head shirt! Links below video description.

    • @dopy8418
      @dopy8418 3 года назад

      @@ChrisGreer Cool

    • @rdp8545
      @rdp8545 2 года назад

      @@ChrisGreer Are you still selling these shirts? I can't see the link you are talking about?

  • @binbin326
    @binbin326 2 года назад +1

    I'm a newbie, your videos help me so much. Thanks for all.

  • @cansizege
    @cansizege 3 года назад +1

    Thanks for valuable information, looking forward to next lesson

  • @NETWizzJbirk
    @NETWizzJbirk 7 месяцев назад

    May I also point out that many modern network devices can do embedded packet captures. You basically filter on direction, interface, and what you would like to match for example, with an access list. it adds a buffer of capture packets, which you can view a summary or export to a PCAP.

  • @patrickmooiman2657
    @patrickmooiman2657 2 года назад

    Perfect explanation. Easy to understand 😀

  • @Joao-uj9km
    @Joao-uj9km 2 года назад

    Thank you a lot!

  • @limitless-codes
    @limitless-codes 21 день назад

    your videos are quality

  • @ChrisGreer
    @ChrisGreer  3 года назад +2

    Where do we capture network traffic and how? In this lesson we will look into where we should place Wireshark to get the best vantage point in our packet captures. Client side? Server side? or both?
    Please smash the like button to let me know if you think this is good content!
    Want some live, hands-on training with Wireshark? Join me on zoom:
    -----------------------LIVE WIRESHARK TRAINING ------------------------
    ▶Network Analysis Fundamentals with Wireshark - bit.ly/virtualwireshark

  • @henrytraining6507
    @henrytraining6507 Год назад +1

    Is Wireshark capable of capturing 10gig interfaces? Im able to capture on the switchport connecting to the server but its 10g and the capture is blank when i open it (also for 10g AP switch interfaces)? Also, Im hoping in a future lesson to see you dissect CAPWAP tunnel data, seems to be alot more in these packets that go to APs interfaces. Thanks!

  • @mail4mikew
    @mail4mikew 2 года назад

    Chris - Great to see you online, fantastic information, I will be watching your other videos soon. It has been a long time since I used wireshark. Are going to cover other interfaces besides ethernet?

    • @ChrisGreer
      @ChrisGreer  2 года назад

      Hey - thanks for the comment. Probably not just because most of the time, people are using Ethernet interfaces to capture, or wifi. So I’d probably do some Wifi content if anything.

  • @aleksandarstoev1611
    @aleksandarstoev1611 2 года назад

    Man I need a private lessons of that man there!

    • @ChrisGreer
      @ChrisGreer  2 года назад

      That can happen! Check out my course at bit.ly/virtualwireshark

  • @bilalbashir
    @bilalbashir Год назад +1

    Hey Chris can you make a video for wireless clients
    I’m tshooting issue of mobile forklifts loosing wireless connection with meraki access points

  • @baqri14
    @baqri14 2 месяца назад

    Nice explanation. I have a question in my case the wireshark is only capturing my local machine. For other machines, it hardly captures the MDNS packets. Please help me out?

  • @vyasG
    @vyasG 2 года назад

    Thank you for this Video. Do you have any video, demonstrating the use of taps? Also, is there any model of tap you would recommend for gigabit ethernet home network(not too expensive) ?

    • @ChrisGreer
      @ChrisGreer  2 года назад +3

      Hi Vyas, not yet, but that is a great idea. I really like the guys at Profitap.com Good people and good product, which are my two requirements when looking for gear.

    • @vyasG
      @vyasG 2 года назад

      @@ChrisGreer Thank you for the suggestion. I visited their website and my initial thought was it would be very expensive! I'll connect with them and check.

  • @BruceFerrell
    @BruceFerrell 3 года назад +1

    What I've been trying to figure out is how to use the remote capture feature!

    • @ChrisGreer
      @ChrisGreer  3 года назад +2

      That's a great idea for a video. Thank you!

  • @dbexclusives
    @dbexclusives 10 месяцев назад +1

    can u tell me what is tap & span? u didn't mention these in your previous videos!

  • @ashleykitson1300
    @ashleykitson1300 10 месяцев назад +1

    What are TAPs and SPAN ports. Kinda followed you about placement of capture until those two terms came up.

  • @draconxx1
    @draconxx1 6 месяцев назад

    By network analyzer, are you referring to a physical tool ?

  • @patdoty788
    @patdoty788 2 года назад

    great videos

  • @ohassairi
    @ohassairi 3 года назад

    hi Chris. is there any way to change the captured packets IP addresses so that i can hide my internal addressing schema? or change any sensitive data in packet details (like username...)

    • @ChrisGreer
      @ChrisGreer  3 года назад +2

      yes there is - you can use a utility called Trace Wrangler - written by my friend Jasper. It is designed to do exactly what you are looking to do. www.tracewrangler.com/

  • @tibtrader
    @tibtrader 2 года назад

    How do you typically capture the server side when its a VMware environment or cloud in a production environment? Do packet brokers help in a data center? Thanks!

    • @ChrisGreer
      @ChrisGreer  2 года назад +2

      Thanks for the comment Tenz. I rarely merge. I do side by side analysis with two different instances of Wireshark open. In a cloud environment, it all depends. If my customer has the support package, we involve AWS support and enlist their help to get a server-side pcap from the virtual network. If that is not available, sometimes the only choice is to get a dumpcap from the server itself. But that is always plan Z.

  • @FarmerAstronaut
    @FarmerAstronaut Год назад

    Lesson #4 and I still don't understand how to start capturing the traffic. Freshly installed wireshark as a portable. 6 interfaces that definitely not what I need. I just need to capture tcp traffic. And I can't figure out how to do this. But instead, I already set up a policy for files and other not important stuff for me. Could you please explain in you videos what are those interfaces I see (in the menu Capture Options) and how to find the right interface to capture my wi-fi traffic?

  • @jfiffick
    @jfiffick 2 года назад +1

    What brand of physical tap do you recommend?

    • @ChrisGreer
      @ChrisGreer  2 года назад +2

      profitap.com has some great stuff out there. Let me know if you need tips on which one to look at.

    • @jfiffick
      @jfiffick 2 года назад +2

      @@ChrisGreer Whats the difference between a $200 tap and a $2000 tap. I know this tap is expensive when they have to quote you for it.

    • @bendono
      @bendono 2 года назад +3

      @@ChrisGreer Would love to see a video discussing physical taps and features to look for, and tips.

  • @joeharyar9873
    @joeharyar9873 3 года назад

    Thanks....

    • @ChrisGreer
      @ChrisGreer  3 года назад

      You bet!

    • @joeharyar9873
      @joeharyar9873 3 года назад

      @@ChrisGreer Hi Chris, I would like to start experimenting troubleshooting network issue (ftp/ssh port block fr example) between computers in my house LAN. Install wireshark on my notebook and ftp/ssh server on another pc....can you suggest which tutorial that able to demonstrate this situation to know if the port is block or not yet open or other issues .... so that I can follow it....thank you.

    • @ChrisGreer
      @ChrisGreer  3 года назад

      @@joeharyar9873 I don't have a specific video to follow along with for that case, but it should be pretty straightforward. Start wireshark on the client, open the ftp or ssh session to the server, stop wireshark. Look at what is happening over port 20, 21, 22, and any other dynamic port between the client and server. You'll get it!

  • @gateteerics8086
    @gateteerics8086 2 года назад

    How do I make my pc a server using wireshark

  • @Meenimie
    @Meenimie 10 месяцев назад

    I am 18, I am following each and every code. It's working. But I have no idea what I am doing.

  • @ooichman
    @ooichman 2 года назад

    This is also called port mirroring

  • @christiangrenier9434
    @christiangrenier9434 2 года назад

    I don't understand how I can monitor all traffic out of my home router! I didn't know that we can do it from the outside world.

    • @ChrisGreer
      @ChrisGreer  2 года назад +1

      You know what I do? I bought a little switch from amazon that does port mirroring. It's only like $50 and it lets me capture everything coming and going from my home network. amzn.to/3IHA9Gk