Text & documents
Numbers & maths
Data & formats
Security
Development & DevOps
Artificial Intelligence
Finance
Health & Wellness
Productivity
Games & Entertainment
Multimedia & design
Business
How to use
What it is

A network capture (.pcap or .pcapng, from Wireshark or tcpdump) explained packet by packet: what happens to each TCP connection, each DNS query and each HTTP request, and why, with the numbers that decide it. The capture is read in your browser and never leaves your device nor is saved.

The same rules as Wireshark

The TCP analysis is translated from Wireshark 4.4’s (its code, not just its manual) and checked against tshark packet by packet on 95 captures: retransmission, fast and spurious retransmission, out of order, duplicate ACKs, zero window, probes, keep-alive and RST. What it does not do: “Window Full”, SACK and MPTCP.

What Wireshark does not tell you

Four things that confuse and are not in the textbooks: a retransmission on timeout cannot be seen from the receiver (the lost segment never reaches the capture); “fast” requires the last duplicate ACK to have been seen less than 20 ms earlier, so it depends on where you capture; Wireshark’s iRTT counts the RST+ACK of a refused connection as the end of the handshake, and is not computed if the SYN has timestamp 0. When it happens, you will see it in the summary.

Practice

The Practice tab asks questions about the capture you have open, yours too: which packets have each problem, one it does NOT have (so as not to invent) and the iRTT. Tick “Hide the analysis” so you do not see the answers while you reply.

Capture labNetwork captures (.pcap) explained: TCP, DNS and HTTP, packet by packet

Capture

Fast retransmission after duplicate ACKs · captured at the client · built for teaching and checked with tshark

Drag your capture here or open it with the button: it is read in your browser, never leaves your device and is not saved.

What is going on

  • Fast retransmission:
  • Duplicate ACK: , , ,
Initial RTT (iRTT): 5.1 msDNS blog.prueba.test: NOERROR → 203.0.119.211 GET /login: 200

What Wireshark does not tell you

At packet 9 a piece is missing that was lost BEFORE reaching the capture point. If its resend arrives on a timeout and in order, from here it will look like a normal segment arriving late: such a retransmission can only be seen capturing at the sender.

N.ºTimeSourceDestinationProtoInfoAnalysis
10.000000192.168.1.4810.0.0.247DNS? blog.prueba.test (id 0x49f4)
20.01700010.0.0.247192.168.1.48DNSNOERROR · blog.prueba.test → CNAME edge.blog.prueba.test, A 203.0.119.211 (id 0x49f4)
30.018000192.168.1.48203.0.119.211TCP52028 → 80 [SYN] Seq=0 Win=64240 Len=0
40.023000203.0.119.211192.168.1.48TCP80 → 52028 [SYN, ACK] Seq=0 Ack=1 Win=64240 Len=0
50.023100192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0
60.023300192.168.1.48203.0.119.211HTTPGET /login HTTP/1.1 (Host: blog.prueba.test) · 52028 → 80 [PSH, ACK] Seq=1 Ack=1 Win=64240 Len=86
70.028300203.0.119.211192.168.1.48TCP80 → 52028 [PSH, ACK] Seq=1 Ack=87 Win=64240 Len=1000
80.028400192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=1001 Win=64240 Len=0
90.028700203.0.119.211192.168.1.48TCP80 → 52028 [PSH, ACK] Seq=2001 Ack=87 Win=64240 Len=1000Previous segment missing
100.028800192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=1001 Win=64240 Len=0Duplicate ACK #1
110.029100203.0.119.211192.168.1.48TCP80 → 52028 [PSH, ACK] Seq=3001 Ack=87 Win=64240 Len=1000
120.029200192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=1001 Win=64240 Len=0Duplicate ACK #2
130.029500203.0.119.211192.168.1.48TCP80 → 52028 [PSH, ACK] Seq=4001 Ack=87 Win=64240 Len=1000
140.029600192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=1001 Win=64240 Len=0Duplicate ACK #3
150.029900203.0.119.211192.168.1.48TCP80 → 52028 [PSH, ACK] Seq=5001 Ack=87 Win=64240 Len=831
160.030000192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=1001 Win=64240 Len=0Duplicate ACK #4
170.035000203.0.119.211192.168.1.48HTTPHTTP/1.1 200 OK · 80 → 52028 [PSH, ACK] Seq=1001 Ack=87 Win=64240 Len=1000Fast retransmission
180.035100192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=87 Ack=5832 Win=64240 Len=0
190.035300192.168.1.48203.0.119.211TCP52028 → 80 [FIN, ACK] Seq=87 Ack=5832 Win=64240 Len=0
200.040300203.0.119.211192.168.1.48TCP80 → 52028 [FIN, ACK] Seq=5832 Ack=88 Win=64240 Len=0
210.040400192.168.1.48203.0.119.211TCP52028 → 80 [ACK] Seq=88 Ack=5833 Win=64240 Len=0

Seq and Ack are relative (as in Wireshark): they count from the initial number of each direction.