Wireshark-users: [Wireshark-users] Interpreting "Retransmission"?
From: "rkruz" <rkruz@xxxxxxx>
Date: Sun, 24 May 2009 17:29:39 -0700
I have a mirrored capture of a simple Ethernet (100BaseT) link as shown
below:
Host > Router/Switch > encryptor> Elec-Optical > Optical-Elec > encryptor >
Routher/switch > Host & separate Mirrored port to WS capture laptop

I see many retransmissions in the Wireshark capture.  Is it fair to say that
the only retransmissions resulting from a link problem would be identified
as TCP protocol?   

I see many retransmissions that are identified as "FTP-Data" or "GIOP" for
example.  Are those retransmission probably a result of the application and
not of an issue on the Ethernet links?

Im suspecting that just focusing on the TCP retransmissions is probably a
better indication of any link issues then all non TCP retranmission and is a
more realistic measure of potential link issues.

Any thoughts appreciated.