Overview
TCP underpins most application traffic. From a PCAP/PCAPNG, you can validate the 3-way handshake, track retransmissions and out-of-order segments, spot flow-control issues (zero window, scaling), and identify MTU/MSS mismatches that create “black holes.”
- What you’ll see: handshake timelines, RTT and RTO trends, retransmits & dup ACKs, window size & scaling, MSS/MTU hints, resets/finishes
- Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
- Works with: HTTP/1.1–2, TLS over TCP, SMTP/IMAP/POP, SSH, RDP, database protocols
What to look for
- Handshake failures: repeated SYNs, SYN/ACK without ACK, early RST/FIN
- Loss & reordering: retransmissions, dup ACK storms, SACK blocks, RTT spikes
- Flow control: zero-window, persist timer behavior, window scaling anomalies
- MTU/MSS issues: small MSS, DF set without ICMP “Frag Needed”, black-hole MTU
- Asymmetry: one-sided retransmits or missing return traffic (routing/firewall)
- Resets: identify which peer sent RST and at what stage (app/middlebox/policy)
Capture tips
- Capture near the client for UX issues; near the gateway for egress/security.
- Include both directions if possible; avoid SPAN oversubscription and LRO/GRO offloads.
- Use a focused time window that reproduces the problem (helps stay within the 10 MB demo limit).
- Record the capture point and time in the filename (e.g.,
clientA_gw_2025-10-25.pcapng).
Example walkthrough
- Filter to the affected host/port.
- Open the conversation view; verify the 3-way handshake and note RTT/TTFB.
- Inspect retransmits, dup ACKs, and SACK; check window size & scaling, MSS values.
- Compare a “good” flow vs the “bad” flow to isolate what changed (RTT, loss, MSS/MTU).
- Export a short report (flows & metrics) and attach it to your ticket.
TCP FAQ
Look for repeated SYNs without SYN-ACK, SYN/ACKs without final ACKs, or early RSTs. The analyzer flags handshake failure patterns and shows who initiated the close.
Network loss shows duplicate ACK storms, SACK blocks, retransmissions, and rising RTOs. Server slowness shows long TTFB/think-time without loss indicators. The analyzer charts these metrics per flow.
Yes. It surfaces MSS values, DF bit symptoms, and missing ICMP “Frag Needed” messages—classic signs of an MTU black hole.
Yes. Even when payloads are encrypted, the tool analyzes handshake timing, retries, and flow control to pinpoint transport issues. You can pivot into TLS and HTTP views where applicable.
A TCP RST indicates an abrupt connection close—often from a middlebox or policy. The analyzer marks the origin and timing so you can identify which endpoint or device reset the session.