Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SRE Book Club - Linux - ch38 - tcpdump & Wireshark
Search
Rico Chen
September 24, 2020
Programming
65
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
SRE Book Club - Linux - ch38 - tcpdump & Wireshark
tcpdump & Wireshark usage
Rico Chen
September 24, 2020
More Decks by Rico Chen
See All by Rico Chen
How to monitor Cosmos validator by Prometheus
ricotoothless
0
650
how-to-choose-cicd-tools.pdf
ricotoothless
0
130
SRE Book Club - Linux - ch45 - Where's socket buffer
ricotoothless
0
180
COSCUP - Dynamic Jenkins Agent on Kubernetes
ricotoothless
0
65
Taiwan CDK Meetup - Rookie operator's CDK journey
ricotoothless
0
250
DevOps Taiwan 2020 Workshop - Jenkins CICD
ricotoothless
0
100
SRE Book Club - Kubernetes - ch32-35 - Network
ricotoothless
0
64
SRE Book Club - Kubernetes - ch22 - Job & CronJob
ricotoothless
0
46
Other Decks in Programming
See All in Programming
AIとRubyの静的型付け
ukin0k0
0
560
AIエージェントの隔離技術の徹底比較
kawayu
0
470
タクシーアプリ『GO』の バックエンド開発のおける AI利活用と若者のすべて
pyama86
3
1.9k
tsserverとは何だったのか、これからどうなるのか
nowaki28
1
460
3Dシーンの圧縮
fadis
1
680
jQueryをバージョンアップする前に使いたいjQuery Migrate
matsuo_atsushi
0
200
AI駆動開発で崩れていくコードベースを立て直す
kyoko_nr_nr
1
450
Modding RubyKaigi for Myself
yui_knk
0
910
コンテキストの使い捨てをやめる — ビジネスルール駆動開発と miko —
ioki
0
180
LLM Plugin for Node-REDの利用方法と開発について
404background
0
160
ローカルLLMを使ってB2Bサービスを作っていての学び
yaotti
0
150
Lessons from Spec-Driven Development
simas
PRO
0
150
Featured
See All Featured
Statistics for Hackers
jakevdp
799
230k
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.8k
Chasing Engaging Ingredients in Design
codingconduct
0
210
XXLCSS - How to scale CSS and keep your sanity
sugarenia
250
1.3M
The Cult of Friendly URLs
andyhume
79
6.9k
Mobile First: as difficult as doing things right
swwweet
225
10k
SEO for Brand Visibility & Recognition
aleyda
0
4.6k
Git: the NoSQL Database
bkeepers
PRO
432
67k
Utilizing Notion as your number one productivity tool
mfonobong
4
320
<Decoding/> the Language of Devs - We Love SEO 2024
nikkihalliwell
1
240
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2.1k
Transcript
CH38 怎麼使用 tcpdump 與 Wireshark 分析網路流量
Agenda • CH38 overview • tcpdump • Wireshark • How
to analyze network traffic? • Lab • Reference
CH38 overview
• Network analysis tool like tcpdump & Wireshark are common
chose to troubleshoot network issue. • tcpdump only supports command line. On the other hand, Wireshark GUI can handle complex network environment.
• PTR (pointer record) provides the IP address associated with
a domain name. • PTR common uses for reverse DNS include: ◦ Anti-spam ◦ Troubleshooting email delivery issues ◦ Logging • Email service: Gsuite, AWS SES, SendGrid, MailGun
tcpdump
• A powerful command-line packet analyzer • tcpdump group github
• tcpdump relate project • How about other command-line? • Wireshark CLI tools & scripting youtube
Wireshark
• A powerful GUI network protocol analyzer • Over 251000
fields in 3000 protocols can filters • Open source with rich community support • SharkFest'20 at 10/12 ~ 10/16 • Many of tutorial resources
How to analyze network traffic?
• Start with client-side • Capture server and client traffic
• Focus on time • The different environment with different filter • Keep your eye on the ball • (resource)
Lab
NLB EKS control plane traefik kube-op s-view
NLB EKS control plane traefik kube-op s-view 115.43.40.158 10.1.8.23 10.1.11.24
10.1.13.131 10.1.6.103 10.1.48.138 10.1.43.161
• what is 169.254.169.254 • Dynamic Configuration of IPv4 Link-Local
Addresses • EKS architectural overview • Elastic network interfaces
NLB EKS control plane traefik kube-op s-view k-proxy
• Application Load Balancer target type
ALB EKS control plane traefik kube-op s-view k-proxy
Reference
• What is a DNS PTR record? • 鳥哥 DNS
正反解 • tcpdump relate project • Wireshark CLI tools & scripting • tcpdump group github • Top 10 Wireshark Filters • Wireshark Display Filter Reference • Wireshark distribution command line
• what is 169.254.169.254 • Dynamic Configuration of IPv4 Link-Local
Addresses • EKS architectural overview • Elastic network interfaces • Network Load Balancer Support in Kubernetes 1.9 • Application Load Balancer target type