Tuesday 24 May 2016

Wireshark Lab IP Solution

Link to download document down below! (Microsoft Word format)

1.  Within the IP packet header, what is the value in the protocol field? What does this value mean?

Answer: The value in the protocol field is ICMP (1). It means the protocol field has only 1 byte.

2.  How many bytes are in the IP header? How many bytes are in the payload of the IP datagram?  Explain how you determined the number of payload bytes.

Answer: There are 20 bytes in the IP header, and 92 bytes total length, this gives 72 bytes in the payload of the IP datagram.

3.  Which fields in the IP datagram always change from one datagram to the next within this series of ICMP messages sent by your computer? Explain why they change.

Answer: Identification, Time to live and Header checksum always change. The identification is a unique value. Different IP packets must have different IDs to identify themselves. TTL always changes because traceroute increments each subsequent packet. Header checksum changes because since header change, checksum must also change.

4.  What is the value in the Identification field and the TTL field?

The value in the identification field is 46463.
The value in the TTL field is 255.

5.  Do these values (referring to question 4) remain unchanged for all of the ICMP TTL-exceeded replies sent to your computer by the nearest (first hop) router?  Why?

Answer: The identification field changes for all the ICMP TTL-exceeded replies because the identification field is a unique value. When two or more IP datagrams have the same identification value, then it means that these IP datagrams are fragments of a single large IP datagram.

The TTL field remains unchanged because the TTL for the first hop router is always the same.

Download Link:

How To Download:
Please disable any Ad Block software if any beforehand or this may not work properly.

1. Please wait for 5 seconds.

2. Click on "Skip Ad".

3. Click on "Download through your browser".


Post a Comment