Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Wireshark RTP Stream - Packet Lost in Neg value over the W

From: "RUOFF, LARS (LARS)** CTR **" <lars.ruoff@xxxxxxxxxxxxxxxxxx>
Date: Mon, 26 Sep 2011 09:44:30 +0200
Hi,
 
No, since you (almost) consistently have -300% all the time, it is most likely that every packet has been seen exactly 4 times by the analysis engine, but no packets have been lost.
(It is an artefact of the RFC3550 lost packets algorithm that duplicate packets are counted as negative losses)
However, as Jaap noted, in order to get more readable data, you should fix your capture setup issue which makes you see every packet multiple times.
 
Regards,
Lars



________________________________

From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Farooq Razzaque
Sent: samedi 24 septembre 2011 19:04
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] Wireshark RTP Stream - Packet Lost in Neg value over the WAN‏


Dear All


 

Can u have a look at the attached screen shot of wireshark. In LOST COLUMN it is showing 300% , -299.7% pack lost. 

 

Do u have any idea that are these packet loss is normal/abnormal.

 

IP phones ( 172.20.24.x) are located in one branch and Recording machine (172.20.19.17) is located in other branch.

 

SPANing is happing over the WAN via L2TPV3.

 

IP Phones : 172.20.24.X (IP Phone)

 

172.20.19.17 (Recording machine)