Wireshark-users: Re: [Wireshark-users] Detecting Duplex Mismatch with Wireshark
From: "Martin Visser" <martinvisser99@xxxxxxxxx>
Date: Fri, 21 Nov 2008 07:37:12 +1100
I agree. If you suspect you have physical layer issues, then the best place to get evidence is the from the error statistics recorded at an interface level on the network equipment. Assuming that this is a managable device (in general this implies it has an IP address and a configuration console) then you should be able to see that stats via the console or via SNMP.

Seeing TCP retransmissions definitely points to look for either physical layer issues or if there are bottlenecks, congestion on links leading to dropped packets.

Regards, Martin

MartinVisser99@xxxxxxxxx


On Fri, Nov 21, 2008 at 5:14 AM, Luis EG Ontanon <luis@xxxxxxxxxxx> wrote:
AFAIK there's little Wireshark can see there, neither mirror (SPAN)
ports nor libpcap pass collisions or garbled frames.

but we know that

duplex mismatch = sensitive increase of collision count on the half-duplex side.
Whic in turn is packet loss and that is AFAIK the only thing wireshark
can infer as there are lots of TCP retransmissions (as well as dup
acks) towards the half-duplex side.

\Lego

On Thu, Nov 20, 2008 at 5:04 PM, Barry Constantine
<Barry.Constantine@xxxxxxxx> wrote:
> Hello,
>
>
>
> Duplex mismatches are still a surprisingly common problem, especially
> between workstations and switches, etc.
>
>
>
> If CDP is present, it is very straight forward to detect duplex mismatches
> in pcap files, since the devices publish the duplex setting in the CDP
> message.
>
>
>
> Does anyone know if there is a way to detect duplex mismatches within a
> normal pcap file (non-CDP) that is captured between two devices with the
> mismatch?
>
>
>
> Thanks,
>
> Barry
>
>
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
>
>



--
This information is top security. When you have read it, destroy yourself.
-- Marshall McLuhan
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users