Packet analysis with Wireshark: DNS, DHCP and the TCP handshake
For network technicians and service desk level 3 staff who have done Packet capture basics and now want to answer everyday tickets ("no IP address", "name won't resolve", "can't connect") from a capture with confidence. You'll write precise display filters, read the four DHCP messages and their key fields, match DNS queries to answers and read response codes, and tell a refused connection from a dropped one, a real retransmission from a capture gap. Ends with a supervisor-graded capture you make and annotate in a lab.
- Level
- Advanced
- Length
- About 75 minutes
- Contents
- 4 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Write Wireshark display filters for DNS, DHCP and TCP questions using field names, comparison operators and sets
- Identify the DHCP discover, offer, request and acknowledge messages in a capture and diagnose a missing, rogue or refused lease
- Match DNS queries to their responses by transaction ID and interpret the response code
- Interpret a TCP connection attempt as completed, refused (RST) or silently dropped, and distinguish a TCP retransmission from a segment that wasn't captured
Course outline
- 1.Capture filters, display filters and the filter languageLesson · 18 min
- 2.DHCP in a captureLesson · 17 min
- 3.DNS in a captureLesson · 13 min
- 4.The TCP connection attempt and Wireshark's analysis flagsLesson · 15 min
- 5.Packet analysis with Wireshark: DNS, DHCP and the TCP handshake: knowledge checkKnowledge check · 14 questions
- 6.Packet analysis with Wireshark: DNS, DHCP and the TCP handshake: practical exerciseKnowledge check · 1 question
- 7.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Wireshark User's Guide 6.4: Building display filter expressions
- Wireshark User's Guide 6.3: Filtering packets while viewing (capture vs display filters)
- Wireshark User's Guide 4.10: Filtering while capturing (capture filters)
- Wireshark User's Guide 7.5: TCP analysis
- Wireshark display filter reference: DHCP
- Wireshark display filter reference: DNS
- Wireshark display filter reference: TCP
- RFC 9293: Transmission Control Protocol (TCP)
- RFC 2131: Dynamic Host Configuration Protocol
- RFC 2132: DHCP Options and BOOTP Vendor Extensions (option 53 message types, server identifier)
- RFC 7766: DNS Transport over TCP, Implementation Requirements
- RFC 1035: Domain Names, Implementation and Specification
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.