PERFORMANCE

How to Track Down Intermittent Packet Loss

Turn brief packet-loss complaints into measurable evidence and a smaller fault domain.

Network performance gauge illustration

Measure long enough to catch the problem

A thirty-second ping is weak evidence when users see trouble every twenty minutes. Run repeated probes across a meaningful interval and record exact timestamps so the results can be compared with interface, carrier, and application events.

Probe more than one destination. Loss to several destinations past the same boundary suggests a shared path, while loss to only one service may point toward the destination, firewall, load balancer, or application.

Correlate loss with counters and utilization

Do not over-trust loss shown only at an intermediate traceroute hop because routers can deprioritize diagnostic replies while forwarding transit traffic normally. Loss becomes more meaningful when it continues to later hops or aligns with the service symptom.

Check queue drops, discards, CRC/FCS errors, optical alarms, and finer-grained utilization. Five-minute averages can hide microbursts that create real packet loss.

Build a before-and-after test

Once you suspect a path or component, define what should change if the theory is correct. Move traffic to a redundant path, replace a suspect jumper, or adjust a queue only after documenting the expected outcome.

A reliable fix should stop the measured loss and improve the original user symptom. The goal is evidence that connects the fault to the repair, not simply a moment when pings happen to look clean.

← Back to all guidesBrowse network tools →
Use these guides as engineering references, not as a substitute for your network design standards, current vendor documentation or production change review.