Protocol · TLS

TLS PCAP Analysis

by My Network Consultant

From capture to clarity—pinpoint TLS handshake, certificate, and negotiation issues with AI-powered insights.

Layer 6/7 (Security) Related: TCP, QUIC, HTTP/2–3, DNS Ports: 443/TCP, 853/TCP (DoT), 465/993/995/TCP TLS 1.2 & 1.3

Overview

Transport Layer Security (TLS) secures most web and application traffic. From a PCAP/PCAPNG you can validate version and cipher negotiation, inspect SNI and certificate chains, confirm session resumption or 0-RTT behavior, and spot handshake retries or alerts. Even when payloads remain encrypted, the handshake and timing tell you why connections fail or lag—whether due to policy, middleboxes, or network conditions.

  • What you’ll see: handshake timeline, versions/ciphers, SNI, cert hints, alerts/retries, resumption & 0-RTT indicators, ALPN negotiation/fallbacks
  • Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
  • Works with: HTTP/2–3, DoT/DoH, IMAPS/SMTPS/POP3S, MQTT over TLS, APIs behind CDNs/reverse proxies

What to look for

  • Handshake failures: repeated ClientHello, HelloRetryRequest loops, early Alerts (handshake_failure, illegal_parameter), abrupt TCP RSTs
  • Version/cipher mismatch: legacy proxies or strict servers causing negotiation failure
  • Certificate issues: self-signed/uncommon issuers, expiry, SNI ≠ CN/SAN, OCSP stapling delays
  • Resumption & 0-RTT: missing tickets/PSK when expected → slower TTFB; 0-RTT retries/declines
  • JA3/JA4 outliers: rare client fingerprints hitting sensitive endpoints
  • ALPN & fallbacks: h3 blocked → fallback to h2/h1; note QUIC handshake retries on UDP/443

Capture tips

  • Capture near the client for user experience timing and near the gateway for policy/middlebox effects.
  • Include DNS to correlate SNI/hostnames and UDP/443 to observe QUIC/TLS 1.3 behavior.
  • Compare a “good” vs “bad” session to isolate deltas (RTT, loss, resumption, ALPN, alerts).
  • Keep captures focused to reproduce the issue (fits within the 10 MB demo limit).
  • Disable LRO/GRO/TSO on capture interfaces to preserve handshake timing and sizes.

Example walkthrough

  1. Browse to TLS flows, plus target hosts.
  2. Open the handshake view: confirm version/cipher, SNI, certificate chain hints, and ALPN result.
  3. Check for Alerts/HelloRetryRequest and note retries or RSTs; compare with a successful flow.
  4. Verify resumption (session tickets/PSK) and look for 0-RTT indicators where expected.
  5. For HTTP/3, observe QUIC handshake retries and any fallback to TCP (HTTP/2/1.1).
  6. Export a brief report (flows, timings, negotiation details) for your ticket.

TLS FAQ

By default we don’t decrypt payloads. With session keys or pre-decrypted captures (when policy allows), header/content analysis is possible. Even without decryption, handshake metadata and timing reveal failure causes.

Look for repeated ClientHello, HelloRetryRequest loops, early Alerts (handshake_failure), or abrupt TCP resets. Check version/cipher lists, SNI, and certificate hints.

JA3/JA4 summarize TLS ClientHello features. Unusual fingerprints can indicate nonstandard clients or malware. We surface outliers and their destinations.

Loss/latency, disabled resumption, OCSP delays, or middlebox policies can slow handshakes. Our timeline breaks down each step to locate the bottleneck.

ALPN selects h2 or h1. For h3, QUIC uses TLS 1.3 over UDP/443; if blocked, you’ll see QUIC retries then a TCP fallback. We display negotiation and fallback steps clearly.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.