This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

greetings, what does "tcp previous segment not captured" indicate? I am running wireshark when trying to connect to a wireless windows 7 vnc server from a wireless ubuntu laptop.

asked 07 Sep '12, 20:05

bishop2001's gravatar image

bishop2001
1111
accept rate: 0%


It means that Wireshark (or whatever program you used to capture the traffic) either wasn't fast enough to cope with the amount of data the NIC received (dropped frames due to performance problems or WiFi "half duplex" operation), or that the frame actually wasn't on the "wire" - meaning, that Wireshark detected packet loss. You usually can tell by looking for a retransmission of the missing packet - if you see it, you most likely didn't suffer dropped frames. Instead, you have packet loss or Out of Order arrivals.

Actually, this message is new replacement in version 1.8.x; in former versions of Wireshark it was "tcp previous segment lost".

permanent link

answered 08 Sep '12, 04:20

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

edited 08 Sep '12, 04:21

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×103
×12
×4

question asked: 07 Sep '12, 20:05

question was seen: 27,976 times

last updated: 08 Sep '12, 04:21

p​o​w​e​r​e​d by O​S​Q​A