Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] TCP round trip time calculations

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Kieran Mansley <kieran@xxxxxxxxxx>
Date: Mon, 08 Jan 2007 10:48:51 +0000

I wonder if anyone could provide some information about how Wireshark
calculates the TCP round trip time (e.g. for the tcp stream graphs)?

If a packet contains payload, and thus is acked, I can see how you can
time the outgoing packet and it's ack and give a round trip time by the
difference between them.  I'm assuming this is how wireshark does it.

If a packet does not contain payload there will be no ack that can be
directly associated with it, and so the above won't work.  A quick look
at the source suggests it might just give the time between acks as the
round trip time in this case.  Is that right or does wireshark do
something more clever?

Many thanks

Kieran





















  • Prev by Date: Re: [Wireshark-users] Analysing MSN traffic
  • Next by Date: [Wireshark-users] Using Wireshark for IP fragments reassembling
  • Previous by thread: Re: [Wireshark-users] Analysing MSN traffic
  • Next by thread: [Wireshark-users] Using Wireshark for IP fragments reassembling
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation