tailieunhanh - practical packet analysis using wireshark to solve real world network problems phần 5

với kịch bản trường hợp thực tế thế giới. Nửa đầu tiên của cuốn sách này cung cấp cho bạn những kiến thức điều kiện tiên quyết, bạn sẽ cần phải hiểu phân tích gói tin và Wireshark. Phần thứ hai của cuốn sách được dành hoàn toàn để | We can leverage various name resolution tools to make our capture files more readable and to save a lot of time in certain situations. For example we can use DNS name resolution to help readily identify the name of a computer we are trying to pinpoint as the source of a particular packet. Types of Name Resolution Tools in Wireshark There are three types of name resolution available in Wireshark MAC name resolution network name resolution and transport name resolution. MAC Name Resolution MAC name resolution uses the ARP protocol to attempt to convert Layer 2 MAC addresses such as 00 09 5B 01 02 03 into Layer 3 addresses such as . If attempts at these conversions fail Wireshark s last resort is to convert the first three bytes of the MAC address into the device s IEEE-specified manufacturer name such as Netgear_01 02 03. Network Name Resolution Network name attempts to convert a Layer 3 address such as the IP address into an easy-to-read DNS name such as MarketingPC1. Transport Name Resolution Transport name resolution attempts to convert a port number into a name associated with it. An example of this would be to display port 80 as http. Enabling Name Resolution To enable name resolution open the Capture Options dialog shown in Figure 5-1 either by choosing Capture Options or by pressing ctrl-K. Potential Drawbacks to Name Resolution Figure 5-1 Enabling name resolution features in the Capture Options dialog Given its benefits using name resolution may seem like a no-brainer but there are some potential drawbacks including the following Sometimes name resolution fails. This may be simply because the name is unknown by the name server the query was sent to. 52 Chopter 5 Name resolution must take place every time you open a specific capture file because this information is not saved in the file. This means that if the servers that a file s name resolution depends upon are not available name resolution will fail. DNS may add .

TỪ KHÓA LIÊN QUAN