Protocol · IP

IP PCAP Analysis

by My Network Consultant

From capture to clarity — pinpoint IPv4/IPv6 issues with AI-powered insights.

Layer 3 · Network Related: ICMP · TCP · UDP · DNS · TLS Protocol numbers: 1 (ICMP) · 6 (TCP) · 17 (UDP) IPv4 & IPv6

Overview

Internet Protocol (IP) is the foundation for routing packets across networks. From a PCAP/PCAPNG you can validate addressing and subnetting, detect fragmentation and Path MTU Discovery (PMTUD) failures, check TTL/Hop Limit behavior, and verify QoS via DSCP/ECN. You can also uncover unusual protocols, traffic to reserved/bogon ranges, and hints of spoofing or asymmetric routing.

  • What you’ll see: IPv4/IPv6 TTL/Hop Limit, fragmentation flags/offsets, ICMP errors (unreachable/frag-needed/time-exceeded), DSCP/ECN markings
  • Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
  • Works with: ICMP for diagnostics; transports like TCP/UDP; upper-layer protocols (HTTP, DNS, TLS)

What to look for

  • Fragmentation & PMTUD: IPv4 MF flag/offsets, IPv6 Fragment header; DF set without ICMP “Fragmentation Needed” → MTU black hole
  • TTL/Hop Limit anomalies: very low values, sudden drops, or asymmetry between directions → routing loops or path changes
  • ICMP signals: Destination Unreachable (admin, port, frag-needed), Time Exceeded → filtering, blocking, or loops
  • Address plan issues: traffic to bogon/reserved ranges, unexpected RFC1918/RFC6598 use, or cross-subnet chatter
  • DSCP/ECN: QoS classifications and congestion marks; verify policies and locate congestion domains
  • Spoofing hints: impossible source subnets, rapid subnet hopping, or conflicts with ARP/ND evidence

Capture tips

  • Capture near the suspected fault domain (client edge, WAN edge, or data center border) to see true TTL/Hop Limit and ICMP.
  • Include ICMP traffic in the capture; PMTUD relies on it for diagnostics.
  • Avoid NIC offloads (LRO/GRO/TSO) during capture to keep IP headers intact.
  • Take a paired capture (client side and gateway) when analyzing asymmetry; compare TTL deltas and ICMP messages.
  • Use a focused time window to reproduce the issue (fits within the 10 MB demo limit).

Example walkthrough

  1. Browse for the IP plus the affected hosts.
  2. Check TTL/Hop Limit distributions per direction; note any sudden drops or large asymmetry.
  3. Inspect fragmentation (IPv4 flags/offsets, IPv6 Fragment header) and look for DF set with large packets.
  4. Review ICMP messages around failures: Destination Unreachable (codes) and Time Exceeded.
  5. Validate DSCP/ECN markings vs expected QoS policy; correlate with loss/latency observations.

IP FAQ

Fragmentation and PMTUD problems, TTL/Hop Limit anomalies, DSCP/ECN markings, checksum errors, traffic to bogon/reserved ranges, and signs of spoofing or asymmetric routing.

Look for fragmented packets (IPv4 flags/offsets, IPv6 Fragment header), small MSS at the transport layer, and missing ICMP “Fragmentation Needed” messages—classic signs of PMTUD failure and MTU black holes.

Yes. Inconsistent TTL/Hop Limit deltas between directions indicate different forward/return paths. The analyzer charts TTL distributions per side.

IPv4 can fragment in transit; IPv6 uses a Fragment extension header and relies on the source for fragmentation. IPv6 replaces TTL with Hop Limit and adds extension headers; our views highlight both families.

DSCP indicates QoS classification and ECN shows congestion without loss. Use these to validate policy and locate congestion domains end-to-end.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.