Throughput line · Throughput & Packet Inspection
Throughput testing and packet inspection tools for “the link is slow” tickets
“How much gets through, and what is on the wire?”
Throughput line6 stops
- iPerf3
- WiresharkAlso on Latency line and Reachability line
- TCPViewAlso on Reachability line
- Obkio Network Performance MonitoringAlso on Latency line
- PingPlotterAlso on Latency line and Reachability line
- mtrAlso on Latency line
Once the path looks clean, the next suspects are capacity and conversation. Throughput tools answer whether a link carries what it should: gigabit between two switches, the bandwidth written into the ISP contract, the site-to-site VPN that users swear is slower than last year. Packet tools answer what the traffic is actually doing — retransmitting, stalling on a zero window, resetting halfway through a handshake, or connecting to a host nobody expected.
Evidence on this line is unusually concrete. An iPerf3 run produces interval-by-interval throughput and retransmit counts that anyone can reproduce with the same two commands. A Wireshark capture is the closest thing networking has to a recording of the incident: a pcap file you can filter down to one conversation and attach to a vendor ticket. TCPView is humbler, a live list of connections per process on one Windows machine, but it answers “which program is holding this port?” in seconds, and sometimes that is the whole ticket.
The trade-off across the line is effort against depth. iPerf3 needs a listener at the far end. Wireshark needs capture access at the right point in the network and someone comfortable reading TCP analysis flags. TCPView needs nothing but a Windows box. The table orders the tools by how much a typical admin can learn in the first fifteen minutes; the methodology page explains how we weigh the rest.
6 throughput and packet tools side by side
iPerf3 leads because a two-command test settles most “is the link slow?” arguments. Obkio, PingPlotter and mtr are supporting tools here: they do not replace a throughput test, but their history shows whether a throughput complaint lines up with loss or latency on the path. Tap a tool name for our review; the vendor link goes to the developer’s site.
| Tool | Licence | Platforms | Evidence it produces | Key feature | Best for |
|---|---|---|---|---|---|
| iPerf3ESnet | Open source | Linux, FreeBSD, macOS (no official Windows builds) | Per-interval throughput, retransmits and UDP loss/jitter figures, with JSON output | Client/server throughput tests over TCP or UDP, with reverse and parallel streams | Answering "is the link actually delivering what we pay for?" between two points you control |
| WiresharkWireshark Foundation | Open source | Windows, macOS, Linux | A pcap file plus expert-info and TCP analysis (retransmissions, zero windows, resets) | Frame-level protocol decoding with TCP stream analysis and I/O graphs | Settling "network or application?" arguments with the actual packets |
| TCPViewMicrosoft Sysinternals | Freeware | Windows 8.1+ and Windows Server 2012+ | A live list of every TCP/UDP endpoint with its owning process, savable as text | Maps each connection and listening port to its owning process; Tcpvcon adds a command line | Finding which Windows process holds a port or keeps opening connections |
| Obkio Network Performance MonitoringObkio | SaaS | Web app; agents for Windows, Linux, Docker, hardware and virtual appliances | Agent-to-agent loss, latency, jitter and VoIP quality history across sites | Monitoring agents at each site that test each other continuously, in both directions | Multi-site or SaaS-heavy teams that need ongoing proof of where performance drops |
| PingPlotterPingman Tools | Commercial | Windows, macOS | Timeline graphs of latency and loss per hop that can be shared or exported | Continuous per-hop latency and loss graphed over time, with a shareable timeline | Proving an intermittent problem to an ISP with a graph instead of a description |
| mtrBitWizard / open-source maintainers | Open source | Linux, BSD, macOS; Windows only via WSL or Cygwin | A plain-text report (--report) of loss and latency per hop, easy to paste into a ticket | Traceroute and ping combined in one live per-hop table, with a report mode for tickets | Admins on Linux or macOS who want path evidence from a shell in under a minute |
Independent comparison — Scan 365 Pro is none of these vendors, and nobody paid for placement. Licences and platforms were checked against each vendor’s own pages on the date above.
How to choose
- Control both ends, or accept a weaker answer
iPerf3 measures between a client and a server you start. Put the server on the far side of the link you are questioning — the other site, the other VLAN, a VM in the same cloud region. Public iPerf3 servers exist, but they measure someone else’s capacity and route as much as yours.
- Test both directions and more than one stream
Run once normally and once with -R so the server sends to the client; asymmetric problems are common on broadband and VPNs. A single TCP stream over a high-latency link is limited by window size, so add parallel streams with -P before blaming the carrier. For voice or video complaints, a UDP run with a target bitrate reports loss and jitter directly.
- Capture at the point that sees the problem
Wireshark on a laptop only sees that laptop’s traffic. For switch or server issues, capture on the server itself, from a mirror (SPAN) port, or with a network TAP. Use a capture filter to keep files small and a ring buffer when you are waiting for an intermittent event.
- Start light before you capture
Plenty of tickets end before a capture is needed. TCPView, or netstat -ano and Get-NetTCPConnection in PowerShell, show which process owns a port and where it connects. Reach for Wireshark when you need to know what happened inside a conversation, not just that it exists.
- Treat captures as sensitive data
A pcap can contain credentials sent over unencrypted protocols, internal hostnames and personal data. Capture only on networks you administer, keep only the conversation you need, and trim or filter files before sending them to a vendor. Store them like any other confidential log.
What a throughput number does — and does not — prove
iPerf3 measures memory-to-memory transfer between two hosts. It deliberately leaves out disks, file-sharing protocols and application logic. If iPerf3 reaches close to line rate but a file copy over SMB still crawls, the network has passed its test and the problem is higher up the stack; that is the moment a packet capture earns its place.
The reverse also holds. A single-stream result well below the contracted speed across a long-distance link may be TCP window limits and latency, not a faulty circuit. Repeat with parallel streams and in both directions before opening a case with the carrier, and include the exact commands in the ticket so the provider can reproduce the test.
Vendor pages: iPerf3 software.es.net · Wireshark wireshark.org · TCPView learn.microsoft.com · Obkio Network Performance Monitoring obkio.com · PingPlotter pingplotter.com · mtr bitwizard.nl
Questions admins ask about throughput and packet tools
Can I test my internet connection with a public iPerf3 server?
You can, as a rough check. The result reflects the path to that server and how busy it is, so it is weaker evidence than a test between two endpoints you control. For a dispute with a provider, run it against a server they nominate or one on the far side of the circuit.
Why is my iPerf3 result lower than the link speed?
Common causes are a single TCP stream on a high-latency path, a slow CPU or virtual NIC on one end, duplex or cabling faults, or genuine congestion. Try parallel streams, the reverse direction and a different pair of hosts to narrow down which of these applies.
Is it safe to run Wireshark on a production server?
Capturing adds CPU and disk load, and the full GUI is heavier than the capture itself. On busy servers many admins capture with the command-line tools that ship with Wireshark (dumpcap or tshark) using a tight capture filter, then open the file on a workstation.
Why use TCPView when netstat exists?
netstat -ano and Get-NetTCPConnection give the same raw facts. TCPView adds process names, a live view that highlights new and closing connections, and the option to close a connection from the list, which saves time while you watch a misbehaving program. The Tcpvcon command-line version covers scripted use.
Can Wireshark capture Wi-Fi traffic?
Capturing your own machine’s traffic over Wi-Fi works on all supported platforms. Seeing other stations’ wireless frames requires monitor mode, which depends on the adapter, driver and operating system. For most troubleshooting it is simpler to capture on the wired side of the access point.
Keep going
Disclosure: vendor links on this page go straight to each vendor’s own site and earn us no commission. See the affiliate disclosure.