Ethereal-users: [Ethereal-users] Newbie asks: TCP "problem" detection?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Joel Noble <jnoble@xxxxxxxx>
Date: Tue, 10 Sep 2002 12:26:42 -0600

I started using Ethereal yesterday in debugging a strange network situation. Works as well as described: kudos, all!

One thing I was looking for, but did not find: some way where Ethereal can draw my attention to evidence of "problems" in TCP sessions, such as:
 - re-transmissions (maybe excessive re-transmissions)
 - slow responses
 - TCP sessions that don't complete a full start-up handshake

Years and years ago, I had a brief exposure to a Network General Sniffer, and it's "Expert" mode made these sorts of high-level correlations, if I recall correctly.

I suspect that pulling these correlations together across many packets isn't something Ethereal does today. Are there any projects to add this in (as a plug in?), or anything like it? Am I missing the obvious? Perhaps a different tool already exists that can be used in conjunction with Ethereal?

Thanks again to the project contributors for such a great tool!

Joel Noble
jnoble@xxxxxxxx