1
1

00:00:00,720  -->  00:00:01,920
<v ->Software tools.</v>
2

2

00:00:01,920  -->  00:00:02,800
In this video,
3

3

00:00:02,800  -->  00:00:04,590
we're going to discuss various software tools
4

4

00:00:04,590  -->  00:00:05,680
that are used in troubleshooting
5

5

00:00:05,680  -->  00:00:08,290
and configuring our networks and network devices.
6

6

00:00:08,290  -->  00:00:10,230
These includes Wi-Fi analyzers,
7

7

00:00:10,230  -->  00:00:12,550
protocol analyzers and packet captures,
8

8

00:00:12,550  -->  00:00:16,070
bandwidth speed test, port scanners, iPerf,
9

9

00:00:16,070  -->  00:00:19,220
NetFlow analyzers, TFTP servers, terminal emulators,
10

10

00:00:19,220  -->  00:00:20,830
and IP scanners.
11

11

00:00:20,830  -->  00:00:23,030
First, we have wireless analyzers,
12

12

00:00:23,030  -->  00:00:24,910
which is a specialized piece of software
13

13

00:00:24,910  -->  00:00:26,900
that can be used to conduct wireless surveys
14

14

00:00:26,900  -->  00:00:28,370
to ensure you have the proper coverage
15

15

00:00:28,370  -->  00:00:30,740
and it helps you prevent any non desired overlap
16

16

00:00:30,740  -->  00:00:33,860
between wireless access point coverage zones and channels.
17

17

00:00:33,860  -->  00:00:35,840
Now, if you're concerned with the channels and use
18

18

00:00:35,840  -->  00:00:37,700
and their signal strength for a given area,
19

19

00:00:37,700  -->  00:00:40,530
you can use a view inside of a Wi-Fi analyzer
20

20

00:00:40,530  -->  00:00:44,000
to display the SSID of each network detected in that area,
21

21

00:00:44,000  -->  00:00:45,340
their relative signal strength
22

22

00:00:45,340  -->  00:00:46,950
and the channel they're using.
23

23

00:00:46,950  -->  00:00:48,430
Here, you can see that most
24

24

00:00:48,430  -->  00:00:50,882
of the 2.4 gigahertz Wi-Fi networks are in use
25

25

00:00:50,882  -->  00:00:52,980
and are centered on channel one
26

26

00:00:52,980  -->  00:00:55,760
with four others being located on channel six.
27

27

00:00:55,760  -->  00:00:58,270
Now channel 11 is not being heavily utilized at all.
28

28

00:00:58,270  -->  00:01:00,850
It only has one network called Home.
29

29

00:01:00,850  -->  00:01:04,010
This is being located on channel 11 as the home network,
30

30

00:01:04,010  -->  00:01:05,990
but there are four other wireless networks
31

31

00:01:05,990  -->  00:01:07,170
located at channel nine
32

32

00:01:07,170  -->  00:01:09,740
and this could cause interference for both channel six
33

33

00:01:09,740  -->  00:01:10,850
and channel 11,
34

34

00:01:10,850  -->  00:01:13,170
as you can clearly see they're overlapping frequencies
35

35

00:01:13,170  -->  00:01:14,850
on this visualization.
36

36

00:01:14,850  -->  00:01:16,370
Now, in addition to this view,
37

37

00:01:16,370  -->  00:01:19,170
you can also overlap the coverage zones on a floor plan
38

38

00:01:19,170  -->  00:01:22,650
using a Wi-Fi analyzer as part of a wireless site survey.
39

39

00:01:22,650  -->  00:01:25,217
This displays the location of the wireless access points
40

40

00:01:25,217  -->  00:01:26,900
and the signal strength that's radiating
41

41

00:01:26,900  -->  00:01:28,690
from each of those access points.
42

42

00:01:28,690  -->  00:01:29,680
In this example,
43

43

00:01:29,680  -->  00:01:31,300
you can see the entire office building
44

44

00:01:31,300  -->  00:01:33,010
is pretty well covered in Wi-Fi
45

45

00:01:33,010  -->  00:01:34,910
as it's shown by the green coverage areas.
46

46

00:01:34,910  -->  00:01:37,180
But, there is a smaller area of yellow and orange
47

47

00:01:37,180  -->  00:01:38,880
on the left-most wall.
48

48

00:01:38,880  -->  00:01:40,110
As you exit the building,
49

49

00:01:40,110  -->  00:01:42,110
you'll see more areas of orange and red,
50

50

00:01:42,110  -->  00:01:45,050
which indicates areas of lower signal strength too.
51

51

00:01:45,050  -->  00:01:46,980
Due to the left wall having a large orange
52

52

00:01:46,980  -->  00:01:48,130
and yellow coverage area,
53

53

00:01:48,130  -->  00:01:50,320
we may want to suggest adding another access point
54

54

00:01:50,320  -->  00:01:52,723
in this area of the building. This would allow us to have
55

55

00:01:52,723  -->  00:01:54,250
more wireless networking capabilities
56

56

00:01:54,250  -->  00:01:56,610
on that part of the building if we needed to.
57

57

00:01:56,610  -->  00:02:00,120
Next, we have protocol analyzers and packet capturing tools.
58

58

00:02:00,120  -->  00:02:02,180
Now a protocol analyzer is used to capture
59

59

00:02:02,180  -->  00:02:04,080
and analyze signals and data traffic
60

60

00:02:04,080  -->  00:02:05,590
over a communication channel.
61

61

00:02:05,590  -->  00:02:06,423
In networking,
62

62

00:02:06,423  -->  00:02:08,810
we most commonly use a software tool known as Wireshark
63

63

00:02:08,810  -->  00:02:10,490
as a protocol analyzer.
64

64

00:02:10,490  -->  00:02:12,680
Now a packet capturing tool is going to be used
65

65

00:02:12,680  -->  00:02:14,930
to capture packets running over a network connection
66

66

00:02:14,930  -->  00:02:15,910
in real time,
67

67

00:02:15,910  -->  00:02:18,090
and then save them for later analysis.
68

68

00:02:18,090  -->  00:02:20,390
This lets you intercept, log and analyze
69

69

00:02:20,390  -->  00:02:21,740
the network traffic and data
70

70

00:02:21,740  -->  00:02:23,890
in order to fully identify classify
71

71

00:02:23,890  -->  00:02:25,470
and troubleshoot network traffic
72

72

00:02:25,470  -->  00:02:28,630
based on its application type, source and destination.
73

73

00:02:28,630  -->  00:02:31,350
The tool like Wireshark contains both a protocol analyzer
74

74

00:02:31,350  -->  00:02:33,250
and a packet capture functionality,
75

75

00:02:33,250  -->  00:02:35,970
making it a great all-in-one tool for you to use.
76

76

00:02:35,970  -->  00:02:38,150
Now, Wireshark and other protocol analyzers
77

77

00:02:38,150  -->  00:02:39,890
are going to be used to troubleshoot your networks
78

78

00:02:39,890  -->  00:02:41,860
when they're experiencing performance issues.
79

79

00:02:41,860  -->  00:02:43,050
By using Wireshark,
80

80

00:02:43,050  -->  00:02:45,030
you can see a breakdown of each packet that's flowing
81

81

00:02:45,030  -->  00:02:45,863
across the network,
82

82

00:02:45,863  -->  00:02:47,610
and you could validate if things are operating
83

83

00:02:47,610  -->  00:02:49,400
as they should inside your network.
84

84

00:02:49,400  -->  00:02:51,580
Cyber security professionals also use Wireshark
85

85

00:02:51,580  -->  00:02:54,190
and other packet captures and protocol analyzers
86

86

00:02:54,190  -->  00:02:55,590
to be able to trace connections,
87

87

00:02:55,590  -->  00:02:58,160
view the contents of suspected network transactions
88

88

00:02:58,160  -->  00:03:01,500
and identify bursts of network traffic as either suspicious,
89

89

00:03:01,500  -->  00:03:03,160
malicious or benign.
90

90

00:03:03,160  -->  00:03:04,410
In addition to Wireshark,
91

91

00:03:04,410  -->  00:03:06,230
there are many other protocol analyzers
92

92

00:03:06,230  -->  00:03:07,320
out there in the field,
93

93

00:03:07,320  -->  00:03:10,780
including Ethereal, Protocol Expert, Netasyst,
94

94

00:03:10,780  -->  00:03:13,550
Network Analyzer, Network Instruments Observer,
95

95

00:03:13,550  -->  00:03:15,650
LanHound and EtherPeek.
96

96

00:03:15,650  -->  00:03:18,520
As for packet capture or packet sniffing tools,
97

97

00:03:18,520  -->  00:03:20,380
Wireshark can also perform this function,
98

98

00:03:20,380  -->  00:03:24,510
but so does tcpdump, WinDump, PRTG Network Monitor,
99

99

00:03:24,510  -->  00:03:27,800
SolarWinds Network Performance Monitor and NetworkMiner.
100

100

00:03:27,800  -->  00:03:30,330
Next, we have bandwidth speed testing tools.
101

101

00:03:30,330  -->  00:03:32,800
There are several local area network speed test tools
102

102

00:03:32,800  -->  00:03:33,633
that exist.
103

103

00:03:33,633  -->  00:03:35,620
And there's also many websites that allow you to conduct
104

104

00:03:35,620  -->  00:03:37,750
an end to end speed test from your client
105

105

00:03:37,750  -->  00:03:39,380
to their internet servers.
106

106

00:03:39,380  -->  00:03:40,820
Now a bandwidth speed test tool
107

107

00:03:40,820  -->  00:03:42,250
should be more accurately described
108

108

00:03:42,250  -->  00:03:43,880
as a throughput test tool though,
109

109

00:03:43,880  -->  00:03:47,000
because remember, real-world throughput is the speed
110

110

00:03:47,000  -->  00:03:49,780
from your client to the end point device and back.
111

111

00:03:49,780  -->  00:03:52,060
Whereas bandwidth is the theoretical limit.
112

112

00:03:52,060  -->  00:03:53,880
Essentially, these tools are going to download
113

113

00:03:53,880  -->  00:03:55,830
a large random file from a server
114

114

00:03:55,830  -->  00:03:58,610
and then turn around and upload it back to that same server.
115

115

00:03:58,610  -->  00:04:00,560
During this download and upload process,
116

116

00:04:00,560  -->  00:04:02,810
the server measures the amount of time it took to download
117

117

00:04:02,810  -->  00:04:04,810
that file and then upload it again.
118

118

00:04:04,810  -->  00:04:07,000
This gives you a real world measure of the throughput
119

119

00:04:07,000  -->  00:04:08,860
across your network from the client,
120

120

00:04:08,860  -->  00:04:10,520
all the way to that server.
121

121

00:04:10,520  -->  00:04:12,620
Now, a local area network version of this,
122

122

00:04:12,620  -->  00:04:14,450
is going to do the same exact thing,
123

123

00:04:14,450  -->  00:04:16,470
but it's going to be conducted by a network appliance
124

124

00:04:16,470  -->  00:04:19,220
or a piece of software that you're connect to the network.
125

125

00:04:19,220  -->  00:04:21,190
This type of speed test works much the same way
126

126

00:04:21,190  -->  00:04:23,280
as the internet speed test I just described,
127

127

00:04:23,280  -->  00:04:25,370
except your data transfer only occurs
128

128

00:04:25,370  -->  00:04:26,710
over the local area network
129

129

00:04:26,710  -->  00:04:28,440
from one client to another client,
130

130

00:04:28,440  -->  00:04:30,130
measuring the time it takes to send and receive
131

131

00:04:30,130  -->  00:04:31,790
that test file locally.
132

132

00:04:31,790  -->  00:04:33,590
If you need to determine if your internet connection
133

133

00:04:33,590  -->  00:04:34,950
is performing adequately,
134

134

00:04:34,950  -->  00:04:36,930
you can use an internet bandwidth speed tests
135

135

00:04:36,930  -->  00:04:38,740
like Speedtest.net.
136

136

00:04:38,740  -->  00:04:39,600
If you need to determine
137

137

00:04:39,600  -->  00:04:41,890
if your local area network performance is adequate,
138

138

00:04:41,890  -->  00:04:44,450
then you're going to use a local area network version of this,
139

139

00:04:44,450  -->  00:04:47,650
something like Lan Speed Test or HELIOS's LanTest software
140

140

00:04:47,650  -->  00:04:49,120
to meet this need.
141

141

00:04:49,120  -->  00:04:50,850
Next, we have port scanners.
142

142

00:04:50,850  -->  00:04:52,540
A port scanner is a software tool
143

143

00:04:52,540  -->  00:04:55,510
that's used to determine which ports are open on a network.
144

144

00:04:55,510  -->  00:04:57,550
Running a port scan on a networker or server,
145

145

00:04:57,550  -->  00:05:00,040
is going to reveal which ports are open and listening
146

146

00:05:00,040  -->  00:05:01,730
or ready to receive information,
147

147

00:05:01,730  -->  00:05:04,050
as well as revealing the presence of security devices,
148

148

00:05:04,050  -->  00:05:06,770
such as firewalls that may be present between the sender
149

149

00:05:06,770  -->  00:05:07,920
and the target.
150

150

00:05:07,920  -->  00:05:10,610
Now a port scan can send a carefully prepared packet
151

151

00:05:10,610  -->  00:05:12,000
to each destination port
152

152

00:05:12,000  -->  00:05:14,110
and then analyze the response it receives back
153

153

00:05:14,110  -->  00:05:15,850
to determine if that port is open,
154

154

00:05:15,850  -->  00:05:17,440
closed or filtered.
155

155

00:05:17,440  -->  00:05:19,090
Now, there are many different software based
156

156

00:05:19,090  -->  00:05:20,530
port scanning tools available.
157

157

00:05:20,530  -->  00:05:21,420
What are the most common,
158

158

00:05:21,420  -->  00:05:23,410
is Nmap, the network mapper,
159

159

00:05:23,410  -->  00:05:25,530
but there are lots of others out there as well,
160

160

00:05:25,530  -->  00:05:28,690
including the SolarWinds Port Scanner and LanSweeper.
161

161

00:05:28,690  -->  00:05:30,340
Next, we have iPerf.
162

162

00:05:30,340  -->  00:05:32,040
iPerf is a software tool that's used
163

163

00:05:32,040  -->  00:05:33,300
to gather an active measurement
164

164

00:05:33,300  -->  00:05:36,680
of a maximum achievable bandwidth on an IP-based network.
165

165

00:05:36,680  -->  00:05:39,150
This is an open source and cross-platform tool
166

166

00:05:39,150  -->  00:05:41,050
that can produce standardized performance measurements
167

167

00:05:41,050  -->  00:05:42,240
for any given network.
168

168

00:05:42,240  -->  00:05:45,120
iPerf has client and server functionality,
169

169

00:05:45,120  -->  00:05:47,250
and it can create data streams to measure the throughput
170

170

00:05:47,250  -->  00:05:49,000
between the two ends of the connection.
171

171

00:05:49,000  -->  00:05:52,170
It can do it in one direction or in both directions.
172

172

00:05:52,170  -->  00:05:54,410
Now, iPerf is going to work by creating TCP
173

173

00:05:54,410  -->  00:05:57,020
and UDP data streams on an IP network
174

174

00:05:57,020  -->  00:05:59,310
and then it's going to measure the throughput of the network
175

175

00:05:59,310  -->  00:06:01,750
as it carries that data back and forth.
176

176

00:06:01,750  -->  00:06:04,180
Next, we have NetFlow analyzers,
177

177

00:06:04,180  -->  00:06:06,430
a NetFlow analyzer is a software tool used
178

178

00:06:06,430  -->  00:06:08,150
to perform monitoring, troubleshooting
179

179

00:06:08,150  -->  00:06:10,240
and in-depth inspection, interpretation
180

180

00:06:10,240  -->  00:06:12,600
and synthesis of traffic flow data.
181

181

00:06:12,600  -->  00:06:14,220
By analyzing NetFlow data,
182

182

00:06:14,220  -->  00:06:16,380
you can more accurately conduct capacity planning
183

183

00:06:16,380  -->  00:06:18,620
and ensure that resources are being appropriately used
184

184

00:06:18,620  -->  00:06:20,950
in support of your organizational goals.
185

185

00:06:20,950  -->  00:06:22,850
For example, using NetFlow data,
186

186

00:06:22,850  -->  00:06:24,820
we can see what types of traffic is consuming
187

187

00:06:24,820  -->  00:06:26,660
all the resources on the network.
188

188

00:06:26,660  -->  00:06:28,320
Is most of your bandwidth being used by people
189

189

00:06:28,320  -->  00:06:29,360
going on Facebook?
190

190

00:06:29,360  -->  00:06:30,350
How about Twitter?
191

191

00:06:30,350  -->  00:06:32,140
What about Gmail or Exchange?
192

192

00:06:32,140  -->  00:06:33,990
Depending on your organizational requirements,
193

193

00:06:33,990  -->  00:06:35,480
you may not want a lot of your bandwidth
194

194

00:06:35,480  -->  00:06:37,630
being used by people browsing social media,
195

195

00:06:37,630  -->  00:06:39,770
but if you're a social media marketing company,
196

196

00:06:39,770  -->  00:06:41,280
you would expect to have a large number of people
197

197

00:06:41,280  -->  00:06:42,760
on Facebook all day working,
198

198

00:06:42,760  -->  00:06:44,690
and that'll be completely appropriate.
199

199

00:06:44,690  -->  00:06:46,120
By using NetFlow, you're going to be able
200

200

00:06:46,120  -->  00:06:49,220
to see that traffic and determine what looks right to you.
201

201

00:06:49,220  -->  00:06:51,880
Now, in addition to looking at specific websites being used,
202

202

00:06:51,880  -->  00:06:53,670
you can also look at the application type
203

203

00:06:53,670  -->  00:06:55,100
that's generating that traffic
204

204

00:06:55,100  -->  00:06:58,280
such as Web, NetBIOS, Voice over IP services,
205

205

00:06:58,280  -->  00:07:00,580
ICNP or even BitTorrents.
206

206

00:07:00,580  -->  00:07:02,610
But understanding the data flows on your network,
207

207

00:07:02,610  -->  00:07:04,320
you can increase your overall performance
208

208

00:07:04,320  -->  00:07:06,530
or even block traffic types that are not generating
209

209

00:07:06,530  -->  00:07:08,400
any value for your business.
210

210

00:07:08,400  -->  00:07:10,650
Next, we have TFTP servers.
211

211

00:07:10,650  -->  00:07:13,420
The Trivial File Transfer Protocol or TFTP,
212

212

00:07:13,420  -->  00:07:15,540
is a simple protocol for exchanging files
213

213

00:07:15,540  -->  00:07:18,030
between two TCP/IP machines.
214

214

00:07:18,030  -->  00:07:20,890
TFTP servers are going to be used for simple file transfers
215

215

00:07:20,890  -->  00:07:21,790
on our network.
216

216

00:07:21,790  -->  00:07:23,880
And they're most commonly used to conduct boot loading
217

217

00:07:23,880  -->  00:07:25,420
of remote devices.
218

218

00:07:25,420  -->  00:07:28,700
TFTP servers are only going to support two functions.
219

219

00:07:28,700  -->  00:07:31,330
They can read files and write files.
220

220

00:07:31,330  -->  00:07:34,470
TFTP servers are often going to be used by embedded devices
221

221

00:07:34,470  -->  00:07:36,310
or systems that retrieve firmware,
222

222

00:07:36,310  -->  00:07:38,460
configuration information or a system image
223

223

00:07:38,460  -->  00:07:40,120
during their boot up process.
224

224

00:07:40,120  -->  00:07:41,330
In our modern networks,
225

225

00:07:41,330  -->  00:07:43,830
many Cisco network devices use TFTP
226

226

00:07:43,830  -->  00:07:45,530
to backup their running configurations
227

227

00:07:45,530  -->  00:07:48,410
and iOS images to a TFTP server.
228

228

00:07:48,410  -->  00:07:51,510
Then, those files can be copied back from the TFTP server
229

229

00:07:51,510  -->  00:07:54,030
to a router or switch later if you need them.
230

230

00:07:54,030  -->  00:07:56,090
Next, we have terminal emulators,
231

231

00:07:56,090  -->  00:07:58,330
a terminal emulator allows a host computer
232

232

00:07:58,330  -->  00:07:59,730
to access another computer,
233

233

00:07:59,730  -->  00:08:00,970
including remote ones
234

234

00:08:00,970  -->  00:08:02,420
through either a command line interface
235

235

00:08:02,420  -->  00:08:06,170
or a graphical one using either Telnet or SSH.
236

236

00:08:06,170  -->  00:08:07,340
For security purposes,
237

237

00:08:07,340  -->  00:08:10,070
we should always be using SSH instead of Telnet though,
238

238

00:08:10,070  -->  00:08:12,740
because Telnet does everything in plain text,
239

239

00:08:12,740  -->  00:08:14,620
that a terminal emulator is going to allow user
240

240

00:08:14,620  -->  00:08:17,490
to access files on the remote computer, transfer files
241

241

00:08:17,490  -->  00:08:19,540
between two computers and remotely control
242

242

00:08:19,540  -->  00:08:20,830
that remote computer.
243

243

00:08:20,830  -->  00:08:22,860
There are many different terminal emulators out there
244

244

00:08:22,860  -->  00:08:24,070
on modern workstations
245

245

00:08:24,070  -->  00:08:26,490
that allow you to connect to a server or network device.
246

246

00:08:26,490  -->  00:08:28,180
But the most popular one on Windows,
247

247

00:08:28,180  -->  00:08:29,550
is known as PuTTY.
248

248

00:08:29,550  -->  00:08:32,160
PuTTY is a free serial console terminal emulator
249

249

00:08:32,160  -->  00:08:36,210
that supports SSH, Telnet, SCP and Rlogin.
250

250

00:08:36,210  -->  00:08:37,980
If you need to connect to a switch or a router
251

251

00:08:37,980  -->  00:08:40,590
in order to configure it over SSH from a Windows client,
252

252

00:08:40,590  -->  00:08:42,540
you're probably going to be using PuTTY.
253

253

00:08:42,540  -->  00:08:44,547
Other terminal emulators include Cmder,
254

254

00:08:44,547  -->  00:08:47,790
the ZOC terminal emulator and Mintty console emulator.
255

255

00:08:47,790  -->  00:08:49,430
If you're working on a Linux client,
256

256

00:08:49,430  -->  00:08:51,510
there's many terminal emulators available,
257

257

00:08:51,510  -->  00:08:54,010
including ones built into the operating system itself.
258

258

00:08:54,010  -->  00:08:55,360
Things like the GNOME terminal,
259

259

00:08:55,360  -->  00:08:57,900
the KDE Konsole and xterm.
260

260

00:08:57,900  -->  00:09:00,330
If you're working on OSX or a Mac machine,
261

261

00:09:00,330  -->  00:09:03,230
there's a built-in terminal program as well called Terminal,
262

262

00:09:03,230  -->  00:09:06,131
or you can download other ones like iTterm2,
263

263

00:09:06,131  -->  00:09:07,840
MacTerm or Kitty.
264

264

00:09:07,840  -->  00:09:09,920
Lastly, we have IP scanners.
265

265

00:09:09,920  -->  00:09:11,520
An IP scanner is a software tool
266

266

00:09:11,520  -->  00:09:13,930
that's used to search for and detect IP addresses
267

267

00:09:13,930  -->  00:09:17,040
and other information related to devices on your network.
268

268

00:09:17,040  -->  00:09:19,240
These tools are going to be used to conduct network management
269

269

00:09:19,240  -->  00:09:20,950
and to identify any route devices
270

270

00:09:20,950  -->  00:09:22,750
that may be connected to your network.
271

271

00:09:22,750  -->  00:09:24,960
There are many IP scanners available for us,
272

272

00:09:24,960  -->  00:09:26,940
including Nmap, the network mapper,
273

273

00:09:26,940  -->  00:09:29,700
Free IP scanner, IP Address Manager,
274

274

00:09:29,700  -->  00:09:32,890
PRTG Network Monitor, Angry IP Scanner,
275

275

00:09:32,890  -->  00:09:36,290
Network Scanner and the IP Range Scanner by LanSweeper.
276

276

00:09:36,290  -->  00:09:37,230
As you may have noticed,
277

277

00:09:37,230  -->  00:09:39,499
many of these IP scanners are the exact same tools
278

278

00:09:39,499  -->  00:09:41,620
as we discussed for port scanners
279

279

00:09:41,620  -->  00:09:43,740
or at least made by the same companies.
280

280

00:09:43,740  -->  00:09:44,870
Now, this is because,
281

281

00:09:44,870  -->  00:09:47,060
like Nmap, many of these tools can first scan
282

282

00:09:47,060  -->  00:09:49,790
for the IP addresses on your network segment,
283

283

00:09:49,790  -->  00:09:51,420
and then they can conduct a deeper scan
284

284

00:09:51,420  -->  00:09:53,950
against each of those IP addresses to scan the ports
285

285

00:09:53,950  -->  00:09:56,100
and the services over those ports.
286

286

00:09:56,100  -->  00:09:56,933
For the exam,
287

287

00:09:56,933  -->  00:09:58,120
it's important for you to understand
288

288

00:09:58,120  -->  00:10:00,370
when you might use a Wi-Fi analyzer,
289

289

00:10:00,370  -->  00:10:02,830
a packet analyzer, a packet capture tool,
290

290

00:10:02,830  -->  00:10:05,480
a bandwidth speed test tool, a port scanner,
291

291

00:10:05,480  -->  00:10:08,720
iPerf, NetFlow analyzers, TFTP servers,
292

292

00:10:08,720  -->  00:10:11,020
terminal emulators or an IP scanner.
293

293

00:10:11,020  -->  00:10:13,260
If you can remember which tool is used for which thing
294

294

00:10:13,260  -->  00:10:14,609
in your network management and troubleshooting,
295

295

00:10:14,609  -->  00:10:16,670
you're going to do fine on test day.
296

296

00:10:16,670  -->  00:10:18,460
But you do not have to remember all the names
297

297

00:10:18,460  -->  00:10:19,710
of all these tools.
298

298

00:10:19,710  -->  00:10:21,820
The only ones you'll probably need to know by name,
299

299

00:10:21,820  -->  00:10:23,970
are things like Nmap and Wireshark,
300

300

00:10:23,970  -->  00:10:25,580
because those are so heavily used
301

301

00:10:25,580  -->  00:10:26,930
in network troubleshooting.
302

302

00:10:27,962  -->  00:10:30,212
(upbeat music)
