User Guide
Wireshark User's Guide
vi
7.3.2. "Expert Info Composite" dialog ................................................................. 114
7.3.3. "Colorized" Protocol Details Tree .............................................................. 114
7.3.4. "Expert" Packet List Column (optional) ...................................................... 115
7.4. Time Stamps .................................................................................................... 115
7.4.1. Wireshark internals ................................................................................. 115
7.4.2. Capture file formats ................................................................................ 116
7.4.3. Accuracy ............................................................................................... 116
7.5. Time Zones ...................................................................................................... 116
7.5.1. Set your computer's time correctly! ............................................................ 117
7.5.2. Wireshark and Time Zones ....................................................................... 118
7.6. Packet Reassembling ......................................................................................... 119
7.6.1. What is it? ............................................................................................ 119
7.6.2. How Wireshark handles it ........................................................................ 119
7.7. Name Resolution .............................................................................................. 120
7.7.1. Name Resolution drawbacks ..................................................................... 120
7.7.2. Ethernet name resolution (MAC layer) ....................................................... 121
7.7.3. IP name resolution (network layer) ............................................................ 121
7.7.4. IPX name resolution (network layer) .......................................................... 122
7.7.5. TCP/UDP port name resolution (transport layer) ........................................... 122
7.8. Checksums ....................................................................................................... 122
7.8.1. Wireshark checksum validation ................................................................. 123
7.8.2. Checksum offloading ............................................................................... 123
8. Statistics .................................................................................................................... 124
8.1. Introduction ..................................................................................................... 124
8.2. The "Summary" window .................................................................................... 124
8.3. The "Protocol Hierarchy" window ........................................................................ 125
8.4. Conversations ................................................................................................... 127
8.4.1. What is a Conversation? .......................................................................... 127
8.4.2. The "Conversations" window .................................................................... 127
8.4.3. The protocol specific "Conversation List" windows ....................................... 128
8.5. Endpoints ........................................................................................................ 128
8.5.1. What is an Endpoint? .............................................................................. 128
8.5.2. The "Endpoints" window ......................................................................... 129
8.5.3. The protocol specific "Endpoint List" windows ............................................ 130
8.6. The "IO Graphs" window ................................................................................... 130
8.7. Service Response Time ...................................................................................... 131
8.7.1. The "Service Response Time DCE-RPC" window ......................................... 132
8.8. Compare two capture files .................................................................................. 132
8.9. WLAN Traffic Statistics ..................................................................................... 134
8.10. The protocol specific statistics windows .............................................................. 134
9. Telephony .................................................................................................................. 135
9.1. Introduction ..................................................................................................... 135
9.2. RTP Analysis ................................................................................................... 135
9.3. VoIP Calls ....................................................................................................... 135
9.4. LTE MAC Traffic Statistics ................................................................................ 136
9.5. LTE RLC Traffic Statistics ................................................................................. 136
9.6. The protocol specific statistics windows ................................................................ 137
10. Customizing Wireshark ............................................................................................... 138
10.1. Introduction .................................................................................................... 138
10.2. Start Wireshark from the command line ............................................................... 138
10.3. Packet colorization .......................................................................................... 144
10.4. Control Protocol dissection ................................................................................ 147
10.4.1. The "Enabled Protocols" dialog box ......................................................... 147
10.4.2. User Specified Decodes .......................................................................... 148