CSIS 100 – Week 4 Lab 2--Wireshark
Packet Analysis Answer Template
Screenshot
#1:
Question #1
How many seconds did your capture run?
Question
2: How many packets did you capture?
Screenshot
#2:
Question
3: What colors are present in your
output?
Question
4: Are there any protocols that appear
with more than one color? Why or why
not?
Screenshot
#3:
Question
5: How many rows are appearing in your
WireShark capture with the filter in place? (Be careful with this...The “No.”
column represents the packet number – not the number of rows currently
visible.)
Question
6: What other protocols do you see in
the “Protocol” column?
Screenshot
#4:
Question
7: What is the host listed directly
below the GET / HTTP/1.1 command in your TCP Stream output?
Question
8: How many bytes is the entire
conversation?
Screenshot
#5:
Question 9:
Compare the IPv4 address listed in your ipconfig output to the IP address that
is listed under the Source column in your Wireshark capture for the first “GET
/ HTTP/1.1” row. Are these IP addresses
the same? Why or why not?
Question
10: Click on the row of the next packet
in this conversation. Does your IP
address appear in the Source or Destination column? Why?
Sun | Mon | Tue | Wed | Thu | Fri | Sat |
---|---|---|---|---|---|---|
1 | 2 | 3 | 4 | 5 | 6 | 7 |
8 | 9 | 10 | 11 | 12 | 13 | 14 |
15 | 16 | 17 | 18 | 19 | 20 | 21 |
22 | 23 | 24 | 25 | 26 | 27 | 28 |
29 | 30 | 1 | 2 | 3 | 4 | 5 |