Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] Mysterious packet loss during capture

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: gkrames@xxxxxxx
Date: Thu, 08 Oct 2009 21:58:57 +0200

Hi all,

I am fighting for a while now with occasional packet loss during
capture in promiscous mode.
Environment: Linux 2.6.27, 32 bit, NIC e1000e, 100MBit network with 
4MBit/s actual traffic (4%), wireshark 1.2.2; 
the capturing PC has <5% CPU load and >1 GB free phys. memory).

My test case captures 100K packets (using the -c) option.
A random number of packets is dropped (about 20..2000) with ever run.

tcpdump, dumpcap, tshark, and wireshark show this behaviour.
Interestingly, tcpdump says "nn packets dropped by kernel".
So this is most likely a kernel/network stack problem.

Trials playing with some kernel sysctl parameters 
(increasing various buffer sizes, decreasing sheduler granularity 
and others) has not improved anything so far.

ethtool -G eth0 rx-usecs 250 (or 125), limitting interrupts
to 4000 or 8000 /sec, has reduced the packet loss but still it is 
there.

Any ideas what else I could try?
Also any hint would be appreciated how to find out why the kernel
decides to drop some packets.

Thanks,
Gerfl






-- 
Jetzt kostenlos herunterladen: Internet Explorer 8 und Mozilla Firefox 3.5 -
sicherer, schneller und einfacher! http://portal.gmx.net/de/go/chbrowser

  • Follow-Ups:
    • Re: [Wireshark-users] Mysterious packet loss during capture
      • From: Abhijit Bare
    • Re: [Wireshark-users] Mysterious packet loss during capture
      • From: Gianluca Varenni
  • Prev by Date: Re: [Wireshark-users] Custom Columns & combining filters
  • Next by Date: Re: [Wireshark-users] Mysterious packet loss during capture
  • Previous by thread: Re: [Wireshark-users] VoIP Calls & old E1 telephony protocols
  • Next by thread: Re: [Wireshark-users] Mysterious packet loss during capture
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation