Wireshark mailing list archives

Re: Wireshark RTP Stream - Packet Lost in Neg value over the WAN‏


From: "RUOFF, LARS (LARS)** CTR **" <lars.ruoff () alcatel-lucent com>
Date: Mon, 26 Sep 2011 09:44:30 +0200

Hi,
 
No, since you (almost) consistently have -300% all the time, it is most likely that every packet has been seen exactly 
4 times by the analysis engine, but no packets have been lost.
(It is an artefact of the RFC3550 lost packets algorithm that duplicate packets are counted as negative losses)
However, as Jaap noted, in order to get more readable data, you should fix your capture setup issue which makes you see 
every packet multiple times.
 
Regards,
Lars



________________________________

From: wireshark-users-bounces () wireshark org [mailto:wireshark-users-bounces () wireshark org] On Behalf Of Farooq 
Razzaque
Sent: samedi 24 septembre 2011 19:04
To: wireshark-users () wireshark org
Subject: [Wireshark-users] Wireshark RTP Stream - Packet Lost in Neg value over the WAN‏


Dear All


 

Can u have a look at the attached screen shot of wireshark. In LOST COLUMN it is showing 300% , -299.7% pack lost. 

 

Do u have any idea that are these packet loss is normal/abnormal.

 

IP phones ( 172.20.24.x) are located in one branch and Recording machine (172.20.19.17) is located in other branch.

 

SPANing is happing over the WAN via L2TPV3.

 

IP Phones : 172.20.24.X (IP Phone)

 

172.20.19.17 (Recording machine) 

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: