A hands-on lab you build on your own machine: install Wireshark and watch real packets — the handshake and headers you just learned — cross your own connection.
Set Up Wireshark Locally
LabIn brief
Objectives
- Install Wireshark locally
- Capture and filter live traffic
- Find a real TCP handshake in your own capture
Everything so far has been theory. Now you will see it for real. Wireshark captures the packets crossing your own machine and shows you exactly what you have been reading about — the handshake, the headers, the layers.
Legal
Only ever capture traffic on a network you own or are authorised to monitor. Capturing on a network you do not control may be an offence under Algerian Law 09-04. On your own machine, on your own connection, you are fine.
Install and capture
- Install Wireshark from your package manager or wireshark.org.
- Open it and pick your active interface (usually
wlan0oreth0). - Type
tcp.port == 443in the filter bar and press Enter. - Open a website in your browser and watch the packets appear.
$ sudo apt install wireshark
Setting up wireshark ...
Do you want non-superusers to capture packets? Yes
Tip
You should see a SYN, a SYN-ACK and an ACK at the very start of each new connection. Find one. That is the handshake from the last section, live on your screen.
Recap
- Wireshark shows the packets crossing your machine
- Only capture on networks you are authorised to
- The theory becomes real once you see the handshake live