Wireshark-users: Re: [Wireshark-users] Wireshark RTP Stream - Packet Lost in Neg value over the W

From: "RUOFF, LARS (LARS)** CTR **" <lars.ruoff@xxxxxxxxxxxxxxxxxx>
Date: Mon, 26 Sep 2011 09:44:30 +0200
No, since you (almost) consistently have -300% all the time, it is most likely that every packet has been seen exactly 4 times by the analysis engine, but no packets have been lost.
(It is an artefact of the RFC3550 lost packets algorithm that duplicate packets are counted as negative losses)
However, as Jaap noted, in order to get more readable data, you should fix your capture setup issue which makes you see every packet multiple times.


From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Farooq Razzaque
Sent: samedi 24 septembre 2011 19:04
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] Wireshark RTP Stream - Packet Lost in Neg value over the WAN‏

Dear All


Can u have a look at the attached screen shot of wireshark. In LOST COLUMN it is showing 300% , -299.7% pack lost. 


Do u have any idea that are these packet loss is normal/abnormal.


IP phones ( 172.20.24.x) are located in one branch and Recording machine ( is located in other branch.


SPANing is happing over the WAN via L2TPV3.


IP Phones : 172.20.24.X (IP Phone) (Recording machine)