

Lab Exercise �nbsp;Protocol Layers
Objective
To learn how protocols and layering are represented in packets. They are key concepts for structuring
networks that are covered in the text.
The trace for this lab is here:
http://scisweb.ulster.ac.uk/~kevin/com320/labs/wireshark/trace-protocol-layers.pcap
(although the main trace you will look at is from a site you pick such as
www.ulster.ac.uk
in the exam-
ples which follow).
Requirements
Wireshark
: This lab uses the Wireshark software tool to capture and examine a packet trace. A packet
trace is a record of traffic at a location on the network, as if a snapshot was taken of all the bits that
passed across a particular wire. The packet trace records a timestamp for each packet, along with the
bits that make up the packet, from the lower-layer headers to the higher-layer contents. Wireshark runs
on most operating systems, including Windows, Mac and Linux. It provides a graphical UI that shows the
sequence of packets and the meaning of the bits when interpreted as protocol headers and data. It col-
or-codes packets by their type, and has various ways to filter and analyze packets to let you investigate
the behavior of network protocols. Wireshark is widely used to troubleshoot networks. You can down-
load it from www.wireshark.org for your personal computer. It is an ideal packet analyzer for our labs
�/p>
it
is
stable,
has
a
large
user
base
and
well-documented
support
that
includes
a
user-guide
http://www.wireshark.org/docs/wsug_html_chunked),
and
a
detailed
FAQ,
rich
functionality
that
in-
cludes the capability to analyze hundreds of protocols, and a well-designed user interface. It operates in
computers using Ethernet, serial (PPP and SLIP), 802.11 wireless LANs, and many other link-layer tech-
nologies (if the OS on which it is running allows Wireshark to do so). It is already installed in the labs.
A quick help guide to Wireshark display filters is here:
http://openmaniak.com/wireshark_filters.php
Wireshark is a c
ore tool for any wireless ‘man in the middleâ€?nbsp;or similar snooping attack. It is simply in-
dispensable for those who wish to examine packets being transferred over a network
�/p>
good or bad�.