Overview
User Datagram Protocol (UDP) is lightweight and connectionless. That makes it fast—but also unforgiving: there’s no handshake, retransmission, or built-in ordering. From a PCAP/PCAPNG you can detect application-layer retries (e.g., DNS), identify silent drops and firewall policy via ICMP Port Unreachable, and diagnose fragmentation or Path MTU Discovery failures when large datagrams are in flight.
- What you’ll see: request/response timing, missing replies, repeated queries, ICMP Port Unreachable/Admin Prohibited, Packet Too Big/Frag Needed, payload sizes vs MTU
- Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
- Works with: DNS over UDP, time sync (NTP), VPN tunnels, service discovery, and UDP/443 traffic patterns
What to look for
- Silent drops: requests without responses; correlate with ICMP Port Unreachable/Admin Prohibited from intermediate hops
- Retries/timeouts: repeated DNS queries or application retries → loss, filtering, or overload
- Fragmentation: unusually large UDP datagrams; missing reassembly; no ICMP feedback → MTU black hole
- Reordering/jitter symptoms: seen via application behavior (e.g., sporadic timeouts or fallback to TCP)
- Checksum “errors” at source: likely NIC offload artifacts rather than real corruption
Capture tips
- Capture near the drop point (edge/gateway) to see ICMP feedback and confirm where packets vanish.
- Include ICMP in the capture—PMTUD and Port Unreachable diagnostics depend on it.
- Disable NIC offloads (LRO/GRO/TSO/checksum) on the capture interface to avoid false checksum errors.
- Use a focused window that reproduces the issue to stay within the 10 MB demo limit.
- For DNS, capture both UDP and TCP 53 to observe truncation and fallbacks.
Example walkthrough
- Browse to the app/hosts in question.
- Measure request→response times and note any missing replies or repeated queries.
- Check for ICMP Port Unreachable/Admin Prohibited or Packet Too Big/Frag Needed around failures.
- Review UDP payload sizes vs expected MTU; flag unusually large datagrams.
UDP FAQ
UDP is connectionless with no retransmissions, so you infer problems from app-level behavior and ICMP feedback rather than transport signals like dup ACKs or SACK.
Look for repeated requests/timeouts (e.g., DNS) and correlate with ICMP errors or filtering at intermediate hops.
They often fragment and get dropped, especially if ICMP is filtered. Prefer smaller payloads or app protocols with recovery.
We surface DNS timing/retries, helping you spot blocking or degradation.
Often due to NIC offload on the sender. Disable offloads during capture or verify on a span/monitor port.