hello,
first I hope that I posted this in the correct location.
I am trying to understand why I am seeing high packet loss and latency and to explain that from a packet capture I am analyzing. I am not sure if this is something that can be shared but if it can it will be very helpful for what i am troubleshooting. I get that I am asking a pretty specific question and understand if what I am asking is something that cannot be shared. I am asking this question so I can confirm that the results I am getting are not artifically introduced because of something I am doing.
A service is created with a probing interval of 10 minutes to an IP address using tcp port 80. Just the other day I am seeing 48% packet loss when looking at the last 24 hours which is super high.
In the packet captures it looks like the probing process is to create a TCP connection and then FIN it. Next there are three TCP connections that are half opened and then reset in succession. (syn, syn-ack, rst). These three connections are reusing the same source port. this process is repeated multiple times. In one example I was looking at it I saw it happen 8 times.
my questions:
latency - is this calculated on the three half open tcp connections rtt on receiving the syn-ack and then averaged out?
packet loss - is this calculated on the failure of receiving an icmp ttl expired packet (the TCP connections begin with an IP TTL of 1)?
thanks for any pointers anyone can provide.