Overview
When users say “the network is slow,” you need packet-level truth. Upload a PCAP/PCAPNG and let the analyzer surface where time is lost — DNS, TLS, transport (TCP/UDP), or the application itself. You’ll see handshake timelines, RTT/RTO trends, retransmissions, MSS/MTU hints, resolver latency, and QUIC/TLS negotiation, all summarized so you can act quickly.
- What you’ll see: flow timelines with RTT/RTO, retransmits & dup ACKs, zero-window events, MSS/MTU indicators, DNS latency & fallbacks, TLS/QUIC negotiation & retries
- Best for: outages, slow apps, intermittent timeouts, WAN degradation, change validation
- Works with: branch/SD-WAN, data center, Wi-Fi/campus, VPNs, CDN/proxy edges
What to look for
- Loss & latency: retransmissions, dup ACK storms, rising RTO, high RTT variance
- Flow control: zero-window, small receive windows, poor scaling → server pressure or middlebox
- MTU/MSS: DF set + no ICMP “Frag Needed”/“Packet Too Big”, small MSS → black-hole MTU
- DNS pathology: >300 ms resolver times, NXDOMAIN/SERVFAIL spikes, TCP fallback from TC flag
- TLS/QUIC: handshake retries/alerts, ALPN downgrades, H3 blocked → fallback to H2/H1
- Asymmetry & routing: TTL/Hop Limit gaps, one-sided loss, unexpected ASNs/hops
Capture tips
- Capture near the client for UX timing and near the edge for egress/WAN policy.
- Include DNS and ICMP to confirm resolver latency and PMTUD symptoms.
- Disable LRO/GRO/TSO/checksum offload on capture NICs to preserve timing and headers.
- Use a focused window that reproduces the issue (fits within the 10 MB demo limit).
- For wireless/campus, consider a capture at the controller/AP switch to see DHCP/Option 82 and roaming effects.
Example walkthrough
- Browse to the symptomatic host/app.
- Check DNS → TLS → TTFB timing; confirm ALPN and session resumption.
- Inspect retransmits/dup ACKs/SACK and window scaling to separate network vs server issues.
- Review MSS/MTU and ICMP evidence for black-hole MTU.
- Compare a “good” vs “bad” flow to isolate the delta; export a short report with evidence.
Common scenarios
- WAN congestion: high RTT + retransmits during peak hours → QoS/traffic shaping review
- Resolver slowdown: >300 ms DNS times → switch resolvers or fix upstream path
- Proxy/CDN edge issue: fast TLS, slow TTFB → origin pressure or cache miss storm
- VPN MTU: path works for small objects, fails on large → tune tunnel MTU/MSS clamp
NOC Troubleshooting FAQ
Network issues show retransmissions, duplicate ACKs, rising RTO, and high RTT variance. Server slowness shows long TTFB and think-time without loss indicators.
Watch for small MSS values, DF set without ICMP Frag Needed/Packet Too Big, and repeated retries. The tool flags PMTUD symptoms and suggests a safe MTU.
Capture client traffic plus UDP/TCP 53 and correlate query→response times, TC flag fallbacks, and NXDOMAIN/SERVFAIL spikes. Include ICMP for PMTUD evidence.
Yes—handshake metadata, ALPN, versions/ciphers, retries, and fallbacks expose transport issues even without decryption.
Near the client for UX timing; at the gateway/WAN edge for egress/policy. Paired captures help confirm asymmetry and isolate the failing segment.