Wireshark: Capturing Re-transmissions for Specific Host

Here is a little tip when working with Wireshark to diagnose problems with traffic flow to a remote host. This filter command shows resent TCP packets for a remote host.

ip.addr eq remote.example.com and (tcp.analysis.retransmission or tcp.analysis.fast_retransmission)

Replace remote.example.com with the name or ip address of the remote host.

Share this post

Leave a comment

Filtered HTML

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.

About Us

Congruity Service is a technology solutions company bringing the best technology solutions to OpenInsight projects, Drupal sites, servers, networks, and your technology needs.