Packet To Sniff
NetworkingBeginner

Watch a TCP handshake in Wireshark

Capture your own web traffic in Wireshark, find the TCP three-way handshake, compare it with a UDP DNS lookup, and learn the display filters analysts use every day.

Published

Objectives

  • Capture traffic on your own network interface
  • Identify SYN, SYN-ACK and ACK packets and follow one TCP stream
  • Compare a UDP DNS query and response with a TCP connection
  • Use display filters to isolate the packets that matter

Time

30 to 40 minutes

Environment

  • Your own computer (Windows, macOS or Linux)
  • Wireshark (free, from wireshark.org)
  • A terminal with curl and nslookup or dig

Packet captures turn networking theory into something you can see. In this lab you capture traffic from your own computer only, and find the handshake described in TCP vs UDP.

Step 1: start a capture

  1. Open Wireshark.
  2. Choose the interface that carries your internet traffic (usually "Wi-Fi" or "Ethernet"; the one with a moving activity graph).
  3. In the capture filter box, enter host example.com or port 53 to keep the capture small. Capture filters decide what is recorded.
  4. Click the blue shark fin to start.

Step 2: generate traffic

In a terminal:

Bash
nslookup example.com
curl -sI https://example.com

The first command sends a DNS query. The second opens a TCP connection to port 443 and fetches the response headers. Then stop the capture.

Step 3: find the DNS exchange (UDP)

Apply the display filter:

Output
dns

You should see a query and a response, usually on UDP port 53. Select the response and expand Domain Name System in the details pane to see the answer records. Two packets, no handshake: that is UDP.

Step 4: find the handshake (TCP)

Apply:

Output
tcp.flags.syn == 1

You will see the SYN from your machine and the SYN, ACK from the server. Right-click the SYN packet, choose Follow > TCP Stream, close the stream window, and Wireshark applies a filter such as tcp.stream eq 0. Now the first three packets are the full handshake:

Output
SYN          your port → 443
SYN, ACK     443 → your port
ACK          your port → 443

Then comes the TLS handshake (Client Hello, Server Hello) and encrypted application data. You cannot read HTTPS content in the capture, which is exactly the point of TLS.

Step 5: measure round-trip time

Select the SYN, ACK packet and expand Transmission Control Protocol > [SEQ/ACK analysis]. Wireshark shows the time since the SYN. That is roughly one round trip between you and the server. Compare it with the DNS query-to-response time.

Step 6: useful filters to practise

Output
tcp.flags.reset == 1           # connections refused or aborted
tcp.analysis.retransmission    # lost segments sent again
tls.handshake.type == 1        # TLS Client Hello
ip.addr == 192.168.1.1         # traffic to or from one address (use your router's)

Expected outcome

  • You can point to the SYN, SYN-ACK and ACK packets and explain each.
  • You can explain why the DNS lookup needed only two packets.
  • You know the difference between a capture filter and a display filter.

Capture only traffic on networks and devices you own or are explicitly authorised to monitor. Capturing other people's traffic without permission can be illegal and is a privacy violation. Captures can contain sensitive data, such as internal hostnames and cookies from unencrypted sites, so store and share .pcap files carefully.