Wireshark-users: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 9

From: Barry Constantine <Barry.Constantine@xxxxxxxx>
Date: Mon, 11 Apr 2011 12:55:55 -0700
OK, it must have been captured on a SPAN port and it has duplicate packets in it.

Thanks a lot Lars!

Barry

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of wireshark-users-request@xxxxxxxxxxxxx
Sent: Monday, April 11, 2011 3:00 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: Wireshark-users Digest, Vol 59, Issue 9

Send Wireshark-users mailing list submissions to
	wireshark-users@xxxxxxxxxxxxx

To subscribe or unsubscribe via the World Wide Web, visit
	https://wireshark.org/mailman/listinfo/wireshark-users
or, via email, send a message with subject or body 'help' to
	wireshark-users-request@xxxxxxxxxxxxx

You can reach the person managing the list at
	wireshark-users-owner@xxxxxxxxxxxxx

When replying, please edit your Subject line so it is more specific
than "Re: Contents of Wireshark-users digest..."


Today's Topics:

   1. Re: Wireshark-users Digest, Vol 59, Issue 8 (Barry Constantine)
   2. Re: Wireshark-users Digest, Vol 59, Issue 8 (Boonie)
   3. Re: VoIP RTP Analysis, Lost Packet Analysis
      (RUOFF, LARS (LARS)** CTR **)
   4. Re: Wireshark-users Digest, Vol 59, Issue 8 (j.snelders)


----------------------------------------------------------------------

Message: 1
Date: Sun, 10 Apr 2011 12:05:35 -0700
From: Barry Constantine <Barry.Constantine@xxxxxxxx>
To: "wireshark-users@xxxxxxxxxxxxx" <wireshark-users@xxxxxxxxxxxxx>
Subject: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 8
Message-ID: <54877A58-BA2A-47EA-B409-998E14218EEB@xxxxxxxx>
Content-Type: text/plain; charset="us-ascii"

Sure, but where do I post the capture file to?

Thanks, Barry


On Apr 10, 2011, at 3:02 PM, "wireshark-users-request@xxxxxxxxxxxxx" <wireshark-users-request@xxxxxxxxxxxxx> wrote:

> Send Wireshark-users mailing list submissions to
>    wireshark-users@xxxxxxxxxxxxx
> 
> To subscribe or unsubscribe via the World Wide Web, visit
>    https://wireshark.org/mailman/listinfo/wireshark-users
> or, via email, send a message with subject or body 'help' to
>    wireshark-users-request@xxxxxxxxxxxxx
> 
> You can reach the person managing the list at
>    wireshark-users-owner@xxxxxxxxxxxxx
> 
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Wireshark-users digest..."
> 
> 
> Today's Topics:
> 
>   1. Re: VoIP RTP Analysis, Lost Packet Analysis (Jake Peavy)
> 
> 
> ----------------------------------------------------------------------
> 
> Message: 1
> Date: Sat, 9 Apr 2011 19:20:42 -0600
> From: Jake Peavy <djstunks@xxxxxxxxx>
> To: Community support list for Wireshark
>    <wireshark-users@xxxxxxxxxxxxx>
> Subject: Re: [Wireshark-users] VoIP RTP Analysis, Lost Packet Analysis
> Message-ID: <BANLkTi=5Ngzq5OJ6jx51VZ0UegZRRzLLFg@xxxxxxxxxxxxxx>
> Content-Type: text/plain; charset="windows-1252"
> 
> On Sat, Apr 9, 2011 at 8:23 AM, Barry Constantine <
> Barry.Constantine@xxxxxxxx> wrote:
> 
>> Hi,
>> 
>> 
>> 
>> I am analyzing VoIP capture files in Wireshark 1.4 and am confused about
>> the RTP analysis results.
>> 
>> 
>> 
>> The jitter results match what I expect, but the packet loss results do not.
>> 
>> 
>> 
>> I know for a fact that the file contains no packet loss and yet the RTP
>> analysis screen reports all packets as lost ?negatively? (and gives an odd
>> -100% value).
>> 
>> 
>> 
>> Any ideas?
>> 
> 
> 
> Can you post a sample capture?
> 
> -- 
> -jp
> 
> They were a proud people. In fact, some said they were too proud. If you
> asked them why they were so proud, they'd just laugh and say, "We're not
> even going to answer that." Later, they were tied to the bumper of a car and
> dragged around the block, as onlookers shrieked with delight. But one old
> man, who had a banjo, just shook his head and walked away. The crowd noticed
> this and set him on fire.
> 
> deepthoughtsbyjackhandey.com
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL: <http://www.wireshark.org/lists/wireshark-users/attachments/20110409/bae58dd6/attachment.html>
> 
> ------------------------------
> 
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
> 
> 
> End of Wireshark-users Digest, Vol 59, Issue 8
> **********************************************


------------------------------

Message: 2
Date: Mon, 11 Apr 2011 07:38:35 +0200
From: "Boonie" <newsboonie@xxxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Subject: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 8
Message-ID: <5D2A5A3B66F6488F95338284682777CC@AMD>
Content-Type: text/plain; format=flowed; charset="iso-8859-1";
	reply-type=original


----- Original Message ----- 
From: "Barry Constantine" <Barry.Constantine@xxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Sent: Sunday, April 10, 2011 9:05 PM
Subject: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 8


> Sure, but where do I post the capture file to?
> 
> Thanks, Barry


You may want to post it here: http://www.cloudshark.org/

But, be aware it is public and you can not erase it.

Dave



------------------------------

Message: 3
Date: Mon, 11 Apr 2011 09:30:22 +0200
From: "RUOFF, LARS (LARS)** CTR **" <lars.ruoff@xxxxxxxxxxxxxxxxxx>
To: Community support list for Wireshark
	<wireshark-users@xxxxxxxxxxxxx>
Subject: Re: [Wireshark-users] VoIP RTP Analysis, Lost Packet Analysis
Message-ID:
	<23C6087F32FB3A43941E25922F87538E21E556F606@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
	
Content-Type: text/plain; charset="us-ascii"


What you describe can happen if you have all packets as duplicates or if they all have the same RTP sequence number.
Your sample capture file will tell us.
If you limit the file to a reasonable size (10 successive RTP packets from the stream will be sufficient to see where the problem is), there's no problem for posting it as an attachment on this list.

Lars



________________________________

From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Barry Constantine
Sent: samedi 9 avril 2011 16:24
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] VoIP RTP Analysis, Lost Packet Analysis



Hi,

 

I am analyzing VoIP capture files in Wireshark 1.4 and am confused about the RTP analysis results.

 

The jitter results match what I expect, but the packet loss results do not.

 

I know for a fact that the file contains no packet loss and yet the RTP analysis screen reports all packets as lost "negatively" (and gives an odd -100% value).

 

Any ideas?

 

Thanks,

Barry



------------------------------

Message: 4
Date: Mon, 11 Apr 2011 10:52:47 +0200
From: "j.snelders" <j.snelders@xxxxxxxxxx>
To: "Community support list for Wireshark"
	<wireshark-users@xxxxxxxxxxxxx>
Subject: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 8
Message-ID: <4CA9A73F000A1BF5@xxxxxxxxxxxxxxxxxxxxxxxxxx>
Content-Type: text/plain; charset="US-ASCII"

You can also use YouSendIt:
www.yousendit.com
It is free for files up to 100MB.

My best
Joke

On Mon, 11 Apr 2011 07:38:35 +0200 Boonie wrote:
>----- Original Message ----- 
>From: "Barry Constantine" <Barry.Constantine@xxxxxxxx>
>To: <wireshark-users@xxxxxxxxxxxxx>
>Sent: Sunday, April 10, 2011 9:05 PM
>Subject: Re: [Wireshark-users] Wireshark-users Digest, Vol 59, Issue 8
>
>
>> Sure, but where do I post the capture file to?
>> 
>> Thanks, Barry
>
>
>You may want to post it here: http://www.cloudshark.org/
>
>But, be aware it is public and you can not erase it.
>
>Dave


       




------------------------------

_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users


End of Wireshark-users Digest, Vol 59, Issue 9
**********************************************