Watch a TCP handshake in Wireshark
Capture your own web traffic in Wireshark, find the TCP three-way handshake, compare it with a UDP DNS lookup, and learn the display filters analysts use every day.
Published
Objectives
- Capture traffic on your own network interface
- Identify SYN, SYN-ACK and ACK packets and follow one TCP stream
- Compare a UDP DNS query and response with a TCP connection
- Use display filters to isolate the packets that matter
Time
30 to 40 minutes
Environment
- Your own computer (Windows, macOS or Linux)
- Wireshark (free, from wireshark.org)
- A terminal with curl and nslookup or dig
Packet captures turn networking theory into something you can see. In this lab you capture traffic from your own computer only, and find the handshake described in TCP vs UDP.
Step 1: start a capture
- Open Wireshark.
- Choose the interface that carries your internet traffic (usually "Wi-Fi" or "Ethernet"; the one with a moving activity graph).
- In the capture filter box, enter
host example.com or port 53to keep the capture small. Capture filters decide what is recorded. - Click the blue shark fin to start.
Step 2: generate traffic
In a terminal:
nslookup example.com
curl -sI https://example.comThe first command sends a DNS query. The second opens a TCP connection to port 443 and fetches the response headers. Then stop the capture.
Step 3: find the DNS exchange (UDP)
Apply the display filter:
dnsYou should see a query and a response, usually on UDP port 53. Select the response and expand Domain Name System in the details pane to see the answer records. Two packets, no handshake: that is UDP.
Step 4: find the handshake (TCP)
Apply:
tcp.flags.syn == 1You will see the SYN from your machine and the SYN, ACK from the server. Right-click the SYN packet, choose Follow > TCP Stream, close the stream window, and Wireshark applies a filter such as tcp.stream eq 0. Now the first three packets are the full handshake:
SYN your port → 443
SYN, ACK 443 → your port
ACK your port → 443Then comes the TLS handshake (Client Hello, Server Hello) and encrypted application data. You cannot read HTTPS content in the capture, which is exactly the point of TLS.
Step 5: measure round-trip time
Select the SYN, ACK packet and expand Transmission Control Protocol > [SEQ/ACK analysis]. Wireshark shows the time since the SYN. That is roughly one round trip between you and the server. Compare it with the DNS query-to-response time.
Step 6: useful filters to practise
tcp.flags.reset == 1 # connections refused or aborted
tcp.analysis.retransmission # lost segments sent again
tls.handshake.type == 1 # TLS Client Hello
ip.addr == 192.168.1.1 # traffic to or from one address (use your router's)Expected outcome
- You can point to the SYN, SYN-ACK and ACK packets and explain each.
- You can explain why the DNS lookup needed only two packets.
- You know the difference between a capture filter and a display filter.
Safety and legal notice
Capture only traffic on networks and devices you own or are explicitly authorised to monitor. Capturing other people's traffic without permission can be illegal and is a privacy violation. Captures can contain sensitive data, such as internal hostnames and cookies from unencrypted sites, so store and share .pcap files carefully.