This is our old Q&A Site. Please post any new questions and answers at

I have two pcaps taken one at the ingress of the device and the other at the egress. The device seems to be dropping the udp packets. The packets have an identification of all 0s Is there a way I can track what packets are missing in the packets at the output.

asked 03 Mar '12, 22:31

Packet's gravatar image

accept rate: 0%

That depends on the way the device alters the packets.

  • If it just switches the packets at Layer-2, then the frames will be exactly the same on the ingress and the egress port. In this case you can use wireshark to generate a MD5 hash on each packet and compare those.
  • When the packets are routed and or natted, then you can compare the length of the packets and maybe the first couple of bytes from the payload. This will work well when there is no packet re-ordering in the device
permanent link

answered 04 Mar '12, 03:15

SYN-bit's gravatar image

SYN-bit ♦♦
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 03 Mar '12, 22:31

question was seen: 3,266 times

last updated: 04 Mar '12, 03:15

p​o​w​e​r​e​d by O​S​Q​A