µ±Ç°Î»ÖãºÊ×Ò³ > һվʽѧϰWireshark - ͼÎÄ
ARP±¨ÎÄ£º
µØÖ·½âÎöÐÒ飬¼´ARP£¨Address Resolution Protocol£©£¬ÊǸù¾ÝIPµØÖ·»ñÈ¡ÎïÀíµØÖ·µÄÒ»¸öTCP/IPÐÒé¡£Æä¹¦ÄÜÊÇ£ºÖ÷»ú½«ARPÇëÇó¹ã²¥µ½ÍøÂçÉϵÄËùÓÐÖ÷»ú£¬²¢½ÓÊÕ·µ»ØÏûÏ¢£¬È·¶¨Ä¿±êIPµØÖ·µÄÎïÀíµØÖ·£¬Í¬Ê±½«IPµØÖ·ºÍÓ²¼þµØÖ·´æÈë±¾»úARP»º´æÖУ¬Ï´ÎÇëÇóʱֱ½Ó²éѯARP»º´æ¡£
×î³õ´ÓPC·¢³öµÄARPÇëÇóÈ·¶¨IPµØÖ·192.168.1.1µÄMACµØÖ·£¬²¢´ÓÏàÁÚϵͳÊÕµ½ARP»Ø¸´¡£ARPÇëÇóÖ®ºó£¬»á¿´µ½ICMP±¨ÎÄ¡£ ICMP±¨ÎÄ£º
ÍøÂç¿ØÖÆÏûϢж¨£¨Internet Control Message Protocol£¬ICMP£©ÓÃÓÚTCP/IPÍøÂçÖз¢ËÍ¿ØÖÆÏûÏ¢£¬Ìṩ¿ÉÄÜ·¢ÉúÔÚͨÐÅ»·¾³Öеĸ÷ÖÖÎÊÌâ·´À¡£¬Í¨¹ýÕâЩÐÅÏ¢£¬Áî¹ÜÀíÕß¿ÉÒÔ¶ÔËù·¢ÉúµÄÎÊÌâ×÷³öÕï¶Ï£¬È»ºó²ÉÈ¡Êʵ±µÄ´ëÊ©½â¾ö¡£ PC·¢ËÍechoÇëÇó£¬ÊÕµ½echo»Ø¸´ÈçÉÏͼËùʾ¡£ping±¨Îı»mark³ÉType 8£¬»Ø¸´±¨ÎÄmark³ÉType 0¡£
Èç¹û¶à´Îpingͬһϵͳ£¬ÔÚPCÉÏɾ³ýARP cache£¬Ê¹ÓÃÈçÏÂARPÃüÁîÖ®ºó£¬»á²úÉúÒ»¸öеÄARPÇëÇó¡£ C:\\> ping 192.168.1.1 ? ping output ?
C:\\> arp ¨Cd * HTTP£º
HTTPÐÒéÊÇĿǰʹÓÃ×î¹ã·ºµÄÒ»ÖÖ»ù´¡ÐÒ飬ÕâµÃÒæÓÚĿǰºÜ¶àÓ¦Óö¼»ùÓÚWEB·½Ê½£¬ÊµÏÖÈÝÒ×£¬Èí¼þ¿ª·¢²¿ÊðÒ²¼òµ¥£¬ÎÞÐè¶îÍâµÄ¿Í»§¶Ë£¬Ê¹ÓÃä¯ÀÀÆ÷¼´¿ÉʹÓá£ÕâÒ»¹ý³Ì¿ªÊ¼ÓÚÇëÇó·þÎñÆ÷´«ËÍÍøÂçÎļþ¡£
´ÓÉÏͼ¿É¼û±¨ÎÄÖаüÀ¨Ò»¸öGETÃüÁµ±HTTP·¢ËͳõʼGETÃüÁîÖ®ºó£¬TCP¼ÌÐøÊý¾Ý´«Êä¹ý³Ì£¬½ÓÏÂÀ´µÄÁ´½Ó¹ý³ÌÖÐHTTP»á´Ó·þÎñÆ÷ÇëÇóÊý¾Ý²¢Ê¹ÓÃTCP½«Êý¾Ý´«»Ø¿Í»§¶Ë¡£´«ËÍÊý¾Ý֮ǰ£¬·þÎñÆ÷ͨ¹ý·¢ËÍHTTP OKÏûÏ¢¸æÖª¿Í»§¶ËÇëÇóÓÐЧ¡£Èç¹û·þÎñÆ÷ûÓн«Ä¿±ê·¢Ë͸ø¿Í»§¶ËµÄÐí¿É£¬½«»á·µ»Ø403 Forbidden¡£Èç¹û·þÎñÆ÷ÕÒ²»µ½¿Í»§¶ËËùÇëÇóµÄÄ¿±ê£¬»á·µ»Ø404¡£
Èç¹ûûÓиü¶àÊý¾Ý£¬Á¬½Ó¿É±»ÖÕÖ¹£¬ÀàËÆÓÚTCPÈý´ÎÎÕÊÖÐźŵÄSYNºÍACK±¨ÎÄ£¬ÕâÀï·¢Ë͵ÄÊÇFINºÍACK±¨ÎÄ¡£µ±·þÎñÆ÷½áÊø´«ËÍÊý¾Ý£¬¾Í·¢ËÍFIN/ACK¸ø¿Í»§¶Ë£¬´Ë±¨Îıíʾ½áÊøÁ¬½Ó¡£½ÓÏÂÀ´¿Í»§¶Ë·µ»ØACK±¨ÎIJ¢ÇÒ¶ÔFIN/ACKÖеÄÐòÁÐ
ºÅ¼Ó1¡£Õâ¾Í´Ó·þÎñÆ÷¶ËÖÕÖ¹ÁËͨÐÅ¡£Òª½áÊøÕâÒ»¹ý³Ì¿Í»§¶Ë±ØÐëÖØÐ¶ԷþÎñÆ÷¶Ë·¢ÆðÕâÒ»¹ý³Ì¡£±ØÐëÔÚ¿Í»§¶ËºÍ·þÎñÆ÷¶Ë¶¼·¢Æð²¢È·ÈÏFIN/ACK¹ý³Ì¡£
һվʽѧϰWireshark£¨Èý£©£ºÓ¦ÓÃWireshark IOͼÐι¤¾ß·ÖÎöÊý¾ÝÁ÷
»ù±¾IO Graphs:
IO graphsÊÇÒ»¸ö·Ç³£ºÃÓõŤ¾ß¡£»ù±¾µÄWireshark IO graph»áÏÔʾץ°üÎļþÖеÄÕûÌåÁ÷Á¿Çé¿ö£¬Í¨³£ÊÇÒÔÿÃëΪµ¥Î»£¨±¨ÎÄÊý»ò×Ö½ÚÊý£©¡£Ä¬ÈÏXÖáʱ¼ä¼ä¸ôÊÇ1Ã룬YÖáÊÇÿһʱ¼ä¼ä¸ôµÄ±¨ÎÄÊý¡£Èç¹ûÏëÒª²é¿´Ã¿ÃëbitÊý»òbyteÊý£¬µã»÷¡°Unit¡±£¬ÔÚ¡°Y Axis¡±ÏÂÀÁбíÖÐÑ¡ÔñÏëÒª²é¿´µÄÄÚÈÝ¡£ÕâÊÇÒ»ÖÖ»ù±¾µÄÓ¦Ó㬶ÔÓڲ鿴Á÷Á¿ÖеIJ¨·å/²¨¹ÈºÜÓаïÖú¡£Òª½øÒ»²½²é¿´£¬µã»÷ͼÐÎÖеÄÈÎÒâµã¾Í»á¿´µ½±¨ÎĵÄϸ½Ú¡£
ΪÁ˽²½â·½±ã£¬µã»÷ʾÀý±¨Îİü£¬»òÓÃ×Ô¼ºµÄwiresharkµã»÷Statistics ¨C IO Graphs¡£Õâ¸ö×¥°üÊÇHTTPÏÂÔØÓöµ½±¨ÎĶªÊ§µÄÇé¿ö¡£
×¢Ò⣺¹ýÂËÌõ¼þΪ¿Õ£¬´ËͼÐÎÏÔʾËùÓÐÁ÷Á¿¡£
Õâ¸öĬÈÏÌõ¼þϵÄÏÔʾÔÚ´ó¶àÊýtroubleshootingÖв¢²»ÊǷdz£ÓÐÓ᣽«YÖá¸ÄΪbits/tickÕâÑù¾Í¿ÉÒÔ¿´µ½Ã¿ÃëµÄÁ÷Á¿¡£´ÓÕâÕÅͼ¿ÉÒÔ¿´µ½·åÖµËÙÂÊÊÇ
300kbps×óÓÒ¡£Èç¹ûÄã¿´µ½ÓÐЩµØ·½Á÷Á¿Ï½µÎªÁ㣬ÄÇ¿ÉÄÜÊÇÒ»¸ö³öÎÊÌâµÄµã¡£Õâ¸öÎÊÌâÔÚͼÉϺܺ÷¢ÏÖ£¬µ«ÔÚ¿´±¨ÎÄÁбíʱ¿ÉÄܲ»ÄÇôÃ÷ÏÔ¡£
¹ýÂË£º
ÿһ¸öͼÐζ¼¿ÉÒÔÓ¦ÓÃÒ»¸ö¹ýÂËÌõ¼þ¡£ÕâÀï´´½¨Á½¸ö²»Í¬µÄgraph£¬Ò»¸öHTTPÒ»¸öICMP¡£¿ÉÒÔ¿´µ½¹ýÂËÌõ¼þÖÐGraph 1ʹÓá°http¡±Graph 2ʹÓá°icmp¡±¡£Í¼ÖпÉÒÔ¿´µ½ºìÉ«ICMPÁ÷Á¿ÖÐÓÐЩ¼ä϶£¬½øÒ»²½·ÖÎö¡£
´´½¨Á½¸öͼÐΣ¬Ò»¸öÏÔʾICMP Echo£¨Type=8£©Ò»¸öÏÔʾICMP Reply£¨Type=0£©¡£Õý³£Çé¿ö϶ÔÓÚÿһ¸öechoÇëÇó»áÓÐÒ»¸öÁ¬ÐøµÄreply¡£ÕâÀïµÄÇé¿öÊÇ£º
¹²·ÖÏí92ƪÏà¹ØÎĵµ