P a g e
When the web page loads, close the client window and wait a couple of seconds
Return to Wireshark and
Save the capture as a file called
. This is important, if you need to return
to the original file after applying display filters.
Type in the Display filter text box
(if accessing from outside Seneca
network. If this does not work ping matrix.senecacollege.ca and get the ip address from the ping
reply message) or
(from Seneca network).This will show the beginning of
your conversation with the matrix server.
Your Wireshark window should look like the screen
Notice the first conversation between your host to the server is a [SYN] packet with an info
number of 49912 (yours will be different).
The latter is a TCP flag which tells the server to open a
connection to the host. Notice SEQ=0. Click on the [SYN] packet and open the drop-down arrow
on the Transmission Control Protocol in the Details pane in the middle Wireshark window.
In the top Wireshark packet list pane, select the second TCP packet, labeled SYN, ACK with the
same info number 49912.