From the course: Wireshark: Malware and Forensics

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Solution: Firewall rules

Solution: Firewall rules - Wireshark Tutorial

From the course: Wireshark: Malware and Forensics

Start my 1-month free trial

Solution: Firewall rules

(upbeat music) - [Instructor] We've opened up smallFlows.pcap and in the display filter, entered tcp.stream equal 60. I'll do a shortcut and just say follow the TCP stream. And then I'll modify that to equal 60, press Enter, and now we have tcp.stream equals 60 go to frame 904. Now it's right there, but if there were a lot of packets to search through I could just go here and go to specified packet and what we'll do is type 904. And there it is, which it was right there but it's just a little shortcut I wanted to show you. Alright, so now what we'll do is go to tools firewall access control list rules. Now, once it open the dialog box defaults at IP tables what I'll do is drop down and select Cisco iOS extended. And then I want you to search for the IP address. 65.54.95.140 and equals port 80, and that's right here. And then we'll say copy, and I'm going to close that. So now what we'll do is we'll just paste it right…

Contents