Networking
Reading a packet capture without drowning
A packet capture is the most complete evidence available and the easiest to waste. Open a large one without a plan and you will scroll for an hour and learn nothing.
Capture narrowly
Filter at capture time, not just at display time. A targeted capture is smaller, faster and more likely to contain the event you care about rather than having rotated past it.
tcpdump -ni eth0 host 10.1.1.5 and port 443 -w /tmp/case.pcap
tcpdump -ni eth0 -s 128 host 10.1.1.5 # headers only
Start with the summary, not the packets
In Wireshark, Statistics before anything else. Protocol Hierarchy tells you what is actually on the wire. Conversations tells you who is talking and how much. Expert Information surfaces retransmissions, resets and malformed frames. Three clicks usually narrows two million frames to the few hundred that matter.
Useful display filters
tcp.analysis.retransmission
tcp.flags.reset == 1
tcp.analysis.zero_window
dns.flags.rcode != 0
http.response.code >= 400
Read the handshake
For any TCP problem, find the SYN. The handshake tells you the round-trip time, the negotiated MSS, whether window scaling and selective acknowledgement were agreed, and how long the server took to respond. Much of the diagnosis is in the first three packets.
Interpret what you find
Retransmissions mean loss somewhere. Zero window means the receiver cannot keep up, which is an application or host problem, not a network one. A reset immediately after the handshake usually means something refused the session deliberately. A long gap between request and response points at the server, not the path.
The habit that matters: decide what you expect to see before you open the file. A capture answers questions. It does not ask them for you.