Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Mysterious packet loss during capture

Date: Thu, 08 Oct 2009 21:58:57 +0200
Hi all,

I am fighting for a while now with occasional packet loss during
capture in promiscous mode.
Environment: Linux 2.6.27, 32 bit, NIC e1000e, 100MBit network with 
4MBit/s actual traffic (4%), wireshark 1.2.2; 
the capturing PC has <5% CPU load and >1 GB free phys. memory).

My test case captures 100K packets (using the -c) option.
A random number of packets is dropped (about 20..2000) with ever run.

tcpdump, dumpcap, tshark, and wireshark show this behaviour.
Interestingly, tcpdump says "nn packets dropped by kernel".
So this is most likely a kernel/network stack problem.

Trials playing with some kernel sysctl parameters 
(increasing various buffer sizes, decreasing sheduler granularity 
and others) has not improved anything so far.

ethtool -G eth0 rx-usecs 250 (or 125), limitting interrupts
to 4000 or 8000 /sec, has reduced the packet loss but still it is 
there.

Any ideas what else I could try?
Also any hint would be appreciated how to find out why the kernel
decides to drop some packets.

Thanks,
Gerfl






-- 
Jetzt kostenlos herunterladen: Internet Explorer 8 und Mozilla Firefox 3.5 -
sicherer, schneller und einfacher! http://portal.gmx.net/de/go/chbrowser