Home page logo

wireshark logo Wireshark mailing list archives

Packet loss
From: Simone Ferlin-Oliveira <ferlin () simula no>
Date: Fri, 30 Aug 2013 19:47:25 +0200


I am investigating several TCP flows and I am wondering how you can proper
filter packet loss in tshark/wireshark:

In the forum someone says that the correct way of filtering lost packets
and looking for tcp.analysis.lost_segments followed by
tcp.analysis.retransmissions. What about tcp.analysis.ack_lost_segments?

How to also correctly capture tcp.analysis.out_of_order without mixing it
with something else?
I am working with MPTCP and I would like to better quantify out of order
packets at the receiver as well as real packet loss (bad link) and not
network delay + retransmission.

I have both client and server trace files. When I use the filters above, I
see slight different values at client and server.

Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

  By Date           By Thread  

Current thread:
  • Packet loss Simone Ferlin-Oliveira (Aug 30)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]