Chapter 7. Advanced Topics

Table of Contents

7.1. Introduction
7.2. Following Protocol Streams
7.3. Show Packet Bytes
7.4. Expert Information
7.4.1. Expert Information Entries
7.4.2. The “Expert Information” Dialog
7.4.3. “Colorized” Protocol Details Tree
7.4.4. “Expert” Packet List Column (Optional)
7.5. TCP Analysis
7.6. Time Stamps
7.6.1. Wireshark Internals
7.6.2. Capture File Formats
7.6.3. Accuracy
7.7. Time Zones
7.7.1. Wireshark and Time Zones
7.8. Packet Reassembly
7.8.1. What Is It?
7.8.2. How Wireshark Handles It
7.8.3. TCP Reassembly
7.9. Name Resolution
7.9.1. Name Resolution Drawbacks
7.9.2. Ethernet Name Resolution (MAC Layer)
7.9.3. IP Name Resolution (Network Layer)
7.9.4. TCP/UDP Port Name Resolution (Transport Layer)
7.9.5. VLAN ID Resolution
7.9.6. SS7 Point Code Resolution
7.10. Checksums
7.10.1. Wireshark Checksum Validation
7.10.2. Checksum Offloading

7.1. Introduction

This chapter will describe some of Wireshark’s advanced features.