jramos 672100ee9d Complete Module 01: Wireshark Fundamentals - full content
Replaced skeleton (1,800 bytes) with complete module (~18KB) including:
- Capture vs Display filters with comparison tables
- SPAN (Switched Port Analyzer) explanation
- The Three Panes walkthrough
- Common display and capture filter reference tables
- File formats (.pcap vs .pcapng)
- Lab 1.1: Deploy the CML Topology (full SW1, RTR1, DHCP-SVR configs)
- Lab 1.2: First Capture — ICMP Ping (step-by-step dissection)
- Lab 1.3: Capture DNS Traffic (query/response analysis)
- Understanding Check questions with answers
- Mermaid network topology diagram
2026-03-01 18:39:45 -07:00

Packet Inspector: DHCP Deep Dive with Wireshark

A comprehensive, hands-on course for network engineers and IT professionals who want to master DHCP troubleshooting using Wireshark packet analysis.

Course Overview

This course takes you from Wireshark fundamentals through advanced DHCP analysis, covering real-world troubleshooting scenarios that network engineers encounter daily. By the end, you'll be able to capture, filter, and interpret DHCP traffic with confidence.

Modules

# Module Description
1 Wireshark Fundamentals Installation, interface, capture filters, and display filters
2 DHCP Message Flow The DORA process, lease lifecycle, and packet-level analysis
3 DHCP Options Common options, vendor-specific extensions, and option overloading
4 DHCP Relay Relay agent operation, Option 82, and cross-subnet DHCP
5 Advanced Wireshark Custom columns, profiles, coloring rules, and scripting
6 Troubleshooting Real-world scenarios, common failures, and systematic debugging
7 DHCPv6 IPv6 address assignment, SLAAC vs DHCPv6, and prefix delegation
8 DHCP Security DHCP snooping, rogue server detection, and starvation attacks

Diagrams

The diagrams/ folder contains visual aids referenced throughout the modules:

  • Diagram 1 - Lab Topology
  • Diagram 2 - DHCP DORA with Relay Flow
  • Diagram 3 - DHCP Packet Structure
  • Diagram 4 - Troubleshooting Flowchart

Prerequisites

  • Basic networking knowledge (IP addressing, subnetting)
  • A computer with Wireshark installed (v3.x or later recommended)
  • Access to a lab environment or virtual network (GNS3, EVE-NG, or physical gear)

License

This course material is provided for educational purposes.

Description
DHCP Deep Dive with Wireshark - Course Materials
Readme 1.2 MiB
Languages
Markdown 100%