Patent attributes
An apparatus for and method of packet loss measurement for TLS connections in an MEN that overcomes the problems of the prior art. The mechanism is operative to ensure that only one copy of each received packet is counted when exiting the TLS connection (unless dropped along the path due to congestion, etc.), so that the number of egress packets counted can be accurately compared with the number of ingress packets counted. Only a single copy of each packet is marked, i.e. flagged, at ingress. Any bridging along the path that needs to duplicate the packet forwards only a single marked copy of the packet. All other copies are forwarded unmarked. At the egress from the TLS, only marked packets are counted by the egress counter. In a second embodiment, a duplication field is inserted into each packet to better track all the duplicate copies of a packet.