

Instructor Note: Using a packet sniffer, such as Wireshark may be considered a breach of the security policy of the school. In Part 2 of this lab, you will use Wireshark to capture and analyze UDP header fields for TFTP file transfers between two Mininet host computers. The terminal command line is used to connect to an anonymous FTP server and download a file. In Part 1 of this lab, you will use the Wireshark open source tool to capture and analyze TCP protocol header fields for FTP file transfers between the host computer and an anonymous FTP server. UDP provides transport layer support for the Domain Name System (DNS) and TFTP, among others. For example, TCP is used to provide transport layer support for the HyperText Transfer Protocol (HTTP) and FTP protocols, among others. Both protocols support upper-layer protocol communication. Two protocols in the TCP/IP transport layer are TCP (defined in RFC 761) and UDP (defined in RFC 768).

Part 1: Identify TCP Header Fields and Operation Using a Wireshark FTP Session Capture.This topology consists of the CyberOps Workstation VM with internet access. Part 1 will highlight a TCP capture of an FTP session.

Instructor Note: Red font color or gray highlights indicate text that appears in the instructor copy only. 10.4.3 Lab – Using Wireshark to Examine TCP and UDP Captures (Instructor Version)
