This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

TCP analysis / interpertation - ACKs and lost segments

0

Hi,

I'm trying to perform TCP analysis, or at least learn how to do it, and I would really appreciate some information about the following filter fields.

tcp.analysis.ack_lost_segment tcp.analysis.lost_segment tcp.analysis.duplicate_ack tcp.analysis.retransmission

I'm not really sure about the first two, since I've read in some places that they might be due to drops in Wireshark while capturing, and might not be a real issue of the TCP stream. This is somewhat confusing :(

Thank you in advance!

asked 18 Jun '12, 04:36

fashasha's gravatar image

fashasha
6113
accept rate: 0%


One Answer:

1

Does this help you?

http://wiki.wireshark.org/TCP_Analyze_Sequence_Numbers

Regards
Kurt

answered 18 Jun '12, 06:00

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Great, it's exactly the page I was looking for! Much appreciated, Kurt.

(18 Jun '12, 07:16) fashasha