Hands-On Project 1-4
In this project, students learn how to create a display filter. A display filter reduces the amount of information that
Wireshark displays from a trace file. This is helpful when a student wants to view only specific traffic captured in
Hands-On Project 1-5
In this project, students examine the contents of captured packets, as decoded and displayed by the protocol
analyzer software. This gives students their first looks into the precise data structures and organizations that
ultimately define what TCP/IP is and how it works. Students build on this foundation, and learn how to read more
into such decodes throughout the rest of this course.
Case Projects Discussion
Case Project 1
The correct answer to this question is “at the hub.” On a hub-based network, such as the one described in this Case
Project, all network traffic must transit through the hub as it’s transmitted by any single machine, and then
forwarded to all other machines. Because the hub is the center of this particular networking environment, it’s the
best place to attach the protocol analyzer. Modern networks are more likely to use switches, and to require use of
Case Project 2
The best arguments for switching to IPv6 (or for supporting dual-stack environments where IPv4 and IPv6 coexist)
include the following factors: improved security, a larger and more flexible address space, and more room to grow
in the future. IPv6 includes numerous enhancements that boost its security across the board as compared to IPv4,
Case Project 3
One obvious method is to check the protocols list in a protocol analyzer that’s set up to run for a day or longer on
the network during normal load and activity conditions. Even if administrators do not capture much data, the