Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] add random packet lost

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Jake Peavy" <djstunks@xxxxxxxxx>
Date: Sun, 6 Jul 2008 06:56:22 -0600

On 7/5/08, Hansang Bae <hbae@xxxxxxxxxx> wrote:
miguel olivares varela wrote:
>
> Hi everybody
>
> i have pcap file and i want to add random packet lost, i tried to use
> editcap
>
> editcap -E 0.05 file.pcap file-error.pcap
>
> but i have a lot of errors not only packet lost.
>
> does anybody help me?


You can't just use editcap.  If you do, you'll lose the packets and
Wireshark will flag the missing packets (prev segment lost).  However,
you won't see retransmissions, fast retansmissions, triple duplicate
acks etc. If you want to see what packet loss looks like, create a
duplex mismatch and push/pull some files via ftp

The OP was trying to simulate loss in a UDP flow - therefore no retransmissions.

If editcap had the right feature this would have been a fine approach to the simulation.

-jp


--
I wouldn't be surprised if someday some fishermen caught a big shark and cut it open, and there inside was a whole person. Then they cut the person open, and in him is a little baby shark. And in the baby shark there isn't a person, because it would be too small. But there's a little doll or something, like a Johnny Combat little toy guy---something like that.

deepthoughtsbyjackhandy.com

  • Follow-Ups:
    • Re: [Wireshark-users] add random packet lost
      • From: Hansang Bae
  • References:
    • Re: [Wireshark-users] add random packet lost
      • From: Hansang Bae
  • Prev by Date: Re: [Wireshark-users] add random packet lost
  • Next by Date: Re: [Wireshark-users] 64-bit Vista
  • Previous by thread: Re: [Wireshark-users] add random packet lost
  • Next by thread: Re: [Wireshark-users] add random packet lost
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation