Overview
Internet Protocol (IP) is the foundation for routing packets across networks. From a PCAP/PCAPNG you can validate addressing and subnetting, detect fragmentation and Path MTU Discovery (PMTUD) failures, check TTL/Hop Limit behavior, and verify QoS via DSCP/ECN. You can also uncover unusual protocols, traffic to reserved/bogon ranges, and hints of spoofing or asymmetric routing.
- What you’ll see: IPv4/IPv6 TTL/Hop Limit, fragmentation flags/offsets, ICMP errors (unreachable/frag-needed/time-exceeded), DSCP/ECN markings
- Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
- Works with: ICMP for diagnostics; transports like TCP/UDP; upper-layer protocols (HTTP, DNS, TLS)
What to look for
- Fragmentation & PMTUD: IPv4 MF flag/offsets, IPv6 Fragment header; DF set without ICMP “Fragmentation Needed” → MTU black hole
- TTL/Hop Limit anomalies: very low values, sudden drops, or asymmetry between directions → routing loops or path changes
- ICMP signals: Destination Unreachable (admin, port, frag-needed), Time Exceeded → filtering, blocking, or loops
- Address plan issues: traffic to bogon/reserved ranges, unexpected RFC1918/RFC6598 use, or cross-subnet chatter
- DSCP/ECN: QoS classifications and congestion marks; verify policies and locate congestion domains
- Spoofing hints: impossible source subnets, rapid subnet hopping, or conflicts with ARP/ND evidence
Capture tips
- Capture near the suspected fault domain (client edge, WAN edge, or data center border) to see true TTL/Hop Limit and ICMP.
- Include ICMP traffic in the capture; PMTUD relies on it for diagnostics.
- Avoid NIC offloads (LRO/GRO/TSO) during capture to keep IP headers intact.
- Take a paired capture (client side and gateway) when analyzing asymmetry; compare TTL deltas and ICMP messages.
- Use a focused time window to reproduce the issue (fits within the 10 MB demo limit).
Example walkthrough
- Browse for the IP plus the affected hosts.
- Check TTL/Hop Limit distributions per direction; note any sudden drops or large asymmetry.
- Inspect fragmentation (IPv4 flags/offsets, IPv6 Fragment header) and look for DF set with large packets.
- Review ICMP messages around failures: Destination Unreachable (codes) and Time Exceeded.
- Validate DSCP/ECN markings vs expected QoS policy; correlate with loss/latency observations.
IP FAQ
Fragmentation and PMTUD problems, TTL/Hop Limit anomalies, DSCP/ECN markings, checksum errors, traffic to bogon/reserved ranges, and signs of spoofing or asymmetric routing.
Look for fragmented packets (IPv4 flags/offsets, IPv6 Fragment header), small MSS at the transport layer, and missing ICMP “Fragmentation Needed” messages—classic signs of PMTUD failure and MTU black holes.
Yes. Inconsistent TTL/Hop Limit deltas between directions indicate different forward/return paths. The analyzer charts TTL distributions per side.
IPv4 can fragment in transit; IPv6 uses a Fragment extension header and relies on the source for fragmentation. IPv6 replaces TTL with Hop Limit and adds extension headers; our views highlight both families.
DSCP indicates QoS classification and ECN shows congestion without loss. Use these to validate policy and locate congestion domains end-to-end.