TCP Packets in Wireshark

I. Answer the following questions about trace file www_umuc_edu.cap.

1. Download trace file www_umuc_edu.cap (see attached) and open it with Wireshark.
2. Find the first TCP handshake. These are packet numbers ____, _____, and _____.
3. What is the IP address of the host that started the handshake? __________________.
4. What is the TCP port connection pair for this handshake? ______, ______.
5. In the first packet of the handshake, the source port is the ephemeral port this host wants to use for the connection, and the destination port indicates the application the host wants to use on the serving host. What application does the host want to use on the serving host?______________
6. Look at packet number 14. Is this part of the conversation initiated by the first handshake? ______

II. Build a filter to see only the first handshake and the conversation for this connection.

1. Click Analyze (or “Edit” on other versions of ethereal) and select Display Filters from the drop-down list. This brings you to the Edit Display Filters List.
2. Click “Expression”
3. Expand TCP (click the plus sign next to TCP), and highlight “Source or Destination Port”.
4. In the Relation section highlight == .
5. In the Value field type the source port used by the host that initiated the conversation. (The source port should be 1097 in this example).
6. Click “OK”. Now there is a filter string in the Edit Display Filter List window. (The filter string should be “tcp.port == 1097”.)
7. In the Filter name box type “Conversation on 1097”.
8. Click New, then OK. Now you have defined a filter (but not yet applied it).

III. Apply the filter to the trace file. Answer question 6.

1. Find the Filter button near the top left corner of the window and click it. (Note for older versions: If you don’t see the Filter button, make sure the browser window is maximized and your task bar is not covering the bottom.)
2. Highlight “Conversation on 1097” and click Apply. Now you can see just this conversation. (You will see the filter string in the filter field. You could also have typed in the filter by hand. You can take the filter off by clicking the Clear button next to the filter field at the bottom.

The handshake establishes the initial sequence numbers for each connection. Try to follow the sequence numbers in the conversation. Now change the display to show relative sequence numbers:

3. Click Edit and select Preferences from the drop-down list.
4. Drill down into Protocols until you get to TCP.
5. Highlight TCP and select the options, “Analyze TCP sequence numbers” and “Relative sequence numbers and window scaling.” Click OK. Try again to follow the sequence numbers.
6. You cannot see the “next sequence number” in the summary pane for packet number 6. Look for it in the protocol tree paneExplain why packet number 7 says “ACK =344.

Order a unique copy of this paper
(550 words)

Approximate price: $22

Basic features
  • Free title page and bibliography
  • Unlimited revisions
  • Plagiarism-free guarantee
  • Money-back guarantee
  • 24/7 support
On-demand options
  • Writer’s samples
  • Part-by-part delivery
  • Overnight delivery
  • Copies of used sources
  • Expert Proofreading
Paper format
  • 275 words per page
  • 12 pt Arial/Times New Roman
  • Double line spacing
  • Any citation style (APA, MLA, Chicago/Turabian, Harvard)

Our guarantees

Delivering a high-quality product at a reasonable price is not enough anymore.
That’s why we have developed 5 beneficial guarantees that will make your experience with our service enjoyable, easy, and safe.

Money-back guarantee

You have to be 100% sure of the quality of your product to give a money-back guarantee. This describes us perfectly. Make sure that this guarantee is totally transparent.

Read more

Zero-plagiarism guarantee

Each paper is composed from scratch, according to your instructions. It is then checked by our plagiarism-detection software. There is no gap where plagiarism could squeeze in.

Read more

Free-revision policy

Thanks to our free revisions, there is no way for you to be unsatisfied. We will work on your paper until you are completely happy with the result.

Read more

Privacy policy

Your email is safe, as we store it according to international data protection rules. Your bank details are secure, as we use only reliable payment systems.

Read more

Fair-cooperation guarantee

By sending us your money, you buy the service we provide. Check out our terms and conditions if you prefer business talks to be laid out in official language.

Read more

Calculate the price of your order

550 words
We'll send you the first draft for approval by September 11, 2018 at 10:52 AM
Total price:
The price is based on these factors:
Academic level
Number of pages

Order your paper today and save 7% with the discount code HOME7