Wireshark/Arp - Wikiversity (2024)

Contents

  • 1 Readings
  • 2 Multimedia
  • 3 Preparation
  • 4 Activity 1 - Capture ARP Traffic
  • 5 Activity 2 - Analyze an ARP Request
  • 6 Activity 3 - Analyze an ARP Reply
  • 7 References
  • 8 See also

Wireshark is a free and open source packet analyzer used for network troubleshooting and analysis. These activities will show you how to use Wireshark to capture and analyze Address Resolution Protocol (ARP) traffic.

Preparation

[edit | edit source]

To prepare for this activity:

  1. Start your computer.
  2. Log in if necessary.
  3. Install Wireshark.

To capture ARP traffic:

  1. Start Wireshark, but do not yet start a capture.
  2. Open an elevated/administrator command prompt.
  3. Use ipconfig to display the default gateway address. Note the Default Gateway displayed.
  4. Start a Wireshark capture.
  5. Use arp -d to clear the ARP cache.
  6. Use ping <default gateway address> to ping the default gateway address.
  7. Use arp -a to view the ARP cache and confirm an entry has been added for the default gateway address.
  8. Close the command prompt.
  9. Stop the Wireshark capture.

Activity 2 - Analyze an ARP Request

[edit | edit source]

To analyze an ARP request:

  1. Observe the traffic captured in the top Wireshark packet list pane. Look for traffic with ARP listed as the protocol. To view only ARP traffic, type arp (lower case) in the Filter box and press Enter.
  2. Select the first ARP packet.
  3. Observe the packet details in the middle Wireshark packet details pane. Notice that it is an Ethernet II / Address Resolution Protocol frame.
  4. Expand Ethernet II to view Ethernet details.
  5. Observe the Destination field. Notice that the destination field is the Ethernet broadcast address (FF:FF:FF:FF:FF:FF). All devices on the network will receive the ARP request.
  6. Observe the Source field. This should contain your MAC address. You can use ipconfig /all, getmac, or ifconfig to confirm.
  7. Observe the Type field. Notice that the type is 0x0806, indicating ARP.
  8. Expand Address Resolution Protocol (request) to view ARP details.
  9. Observe the Sender MAC address. Notice that the sender MAC address is your MAC address.
  10. Observe the Sender IP address. Notice that the sender IP address is your IP address.
  11. Observe the Target MAC address. Notice that the target MAC address is all zeros, because the target MAC address is unknown at this point.
  12. Observe the Target IP address. Notice that the target IP address is the IP address of the default gateway.

Activity 3 - Analyze an ARP Reply

[edit | edit source]

To analyze an ARP reply:

  1. Select the second ARP packet.
  2. Observe the packet details in the middle Wireshark packet details pane. Notice that it is an Ethernet II / Address Resolution Protocol frame. Confirm that in the middle packet details pane that the packet is labeled Address Resolution Protocol (reply).
  3. Expand Ethernet II to view Ethernet details.
  4. Observe the Destination field. Notice that the destination field is your MAC address.
  5. Observe the Source field. This should be the MAC address of the default gateway.
  6. Observe the Type field. Notice that the type is 0x0806, indicating ARP.
  7. Expand Address Resolution Protocol (reply) to view ARP details.
  8. Observe the Sender MAC address. Notice that the sender MAC address is the MAC address of the default gateway.
  9. Observe the Sender IP address. Notice that the sender IP address is the IP address of the default gateway.
  10. Observe the Target MAC address. Notice that the destination MAC address is your MAC address.
  11. Observe the Target IP address. Notice that the destination IP address is your IP address.
  12. Close Wireshark to complete this activity. Quit without Saving to discard the captured traffic.

References

[edit | edit source]

See also

[edit | edit source]

Wireshark/Arp - Wikiversity (2024)
Top Articles
Risk Profiler
Drones Following Me - Understanding the Reasons and Unraveling the Mystery
Antisis City/Antisis City Gym
This website is unavailable in your location. – WSB-TV Channel 2 - Atlanta
Christian McCaffrey loses fumble to open Super Bowl LVIII
Walgreens Boots Alliance, Inc. (WBA) Stock Price, News, Quote & History - Yahoo Finance
Skyward Houston County
Melson Funeral Services Obituaries
Black Gelato Strain Allbud
Flat Twist Near Me
270 West Michigan residents receive expert driver’s license restoration advice at last major Road to Restoration Clinic of the year
Echo & the Bunnymen - Lips Like Sugar Lyrics
Morgan And Nay Funeral Home Obituaries
Best Forensic Pathology Careers + Salary Outlook | HealthGrad
Costco Gas Foster City
Praew Phat
Pasco Telestaff
Nsa Panama City Mwr
Sadie Sink Reveals She Struggles With Imposter Syndrome
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Criterion Dryer Review
Rugged Gentleman Barber Shop Martinsburg Wv
Downloahub
Scat Ladyboy
The Ride | Rotten Tomatoes
Telegram update adds quote formatting and new linking options
Toonily The Carry
Delaware judge sets Twitter, Elon Musk trial for October
Timberwolves Point Guard History
All-New Webkinz FAQ | WKN: Webkinz Newz
Florida Lottery Claim Appointment
Umd Men's Basketball Duluth
Lamp Repair Kansas City Mo
Powerspec G512
Vérificateur De Billet Loto-Québec
Elven Steel Ore Sun Haven
Random Animal Hybrid Generator Wheel
UWPD investigating sharing of 'sensitive' photos, video of Wisconsin volleyball team
La Qua Brothers Funeral Home
Dietary Extras Given Crossword Clue
Madden 23 Can't Hire Offensive Coordinator
San Diego Padres Box Scores
18 Seriously Good Camping Meals (healthy, easy, minimal prep! )
Sams La Habra Gas Price
Craigslist Indpls Free
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Metra Union Pacific West Schedule
Les BABAS EXOTIQUES façon Amaury Guichon
7 National Titles Forum
Latest Posts
Article information

Author: Kelle Weber

Last Updated:

Views: 5864

Rating: 4.2 / 5 (73 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Kelle Weber

Birthday: 2000-08-05

Address: 6796 Juan Square, Markfort, MN 58988

Phone: +8215934114615

Job: Hospitality Director

Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.