This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How do you capture internet connects and disconnects?

0

I am a subscriber to Frontier DSL Internet service (only because of rural location) My internet connection is not totally reliable. There are sporadic disconnections and then reconnections, all at various times of the day and evening. Frontier claims that all their tests so far show the elements of connections are nominal. I claim they're not.

A technician is coming tomorrow to do an inside-the-house service call. I would like to be able to demonstrate the disconnections.

I downloaded WireShark hoping that it could generate a simple report of the disconnections and reconnections. I don't need a lot of data and detail, but the connectivity issue is something we are going to have an argument or several about. Is that possible with WireShark?

It is a fantastic piece of software, and brilliantly conceived and executed, but way above my head. Would appreciate some thoughtful hand-holding. Thank you

asked 22 Apr '15, 18:05

garryuws's gravatar image

garryuws
11114
accept rate: 0%


One Answer:

1

There are several remarks that can be made here.

1) Capture interface

Wireshark can capture from various types on interfaces (Ethernet, USB, BT), but (without special hardware) not from DSL. So any physical layer or data link layer problems on the DSL can't be captured directly.

2) Modem

Your modem may provide valuable sources of information (something the tech will look at I guess) in internal logs. Depending on the type and configuration of the modem this may be accessible. Also the modem may provide a DSL capture interface which can be used to create capture files, which you can read with Wireshark.

Note: this very much depends on the type of modem. Many do not provide these features.

3) Test

You can test your link by having a continues ping running to a known external host. If your link goes down your ping replies stop coming in. This you can capture with Wireshark as well (although it doesn't point to any cause).

4) Timing

With the tech coming in you are already late to show a pattern, which should be taken on longer interval (days/weeks). Depending on the frequency of the occurrences it may be enough.

Good luck.

answered 22 Apr '15, 23:20

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

Japp Many thanks for taking the time to share your expertise, excellent information and very helpful responses.

Your #3 is the best and most practical in this situation, given my relative inexperience.

Soooooooo..... If I may knock on your door for a little bit additional help......... How do I get Wireshark to generate pings? How do I filter out everything except the PING data from the report? Would greatly appreciate your assistance. Many thanks

/gh

(23 Apr '15, 14:08) garryuws

Jaap, I meant. sorry for the typo.

(23 Apr '15, 14:09) garryuws
1

Wireshark doesn't generate pings, or any other network test traffic, it's a packet analyzer.

You can ping from the command prompt, or there are any number of fancy GUI tools that can do the same. Google will help here.

(23 Apr '15, 14:19) grahamb ♦