- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Retransmission of packets on the gateway pcap ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Retransmission of packets on the gateway pcap but not on client pcap
Hello guys, This is a strange issue we are facing in which the client is able to access the server on port 80 but the resources hosted on the server works sometimes and does not work sometime. In the tcpdump pcap file catures on security gateway I see many retransmissions are there but on pcap file of client machine I do not see retransmissions.
The client is directly connected to the checkpoint direwall and Ipsec tunnel has been build netween the checkpoint and ASA firewall and behind ASA firewall the server is hosted.
Anyone faced this kind of issue? Could this be related to checkpoint or tunnel?
Thanks in advance!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless one end of the cable is the Check Point device and the other end is the server, there is something "in between." 😉
Reminds me of a problem I ran into when I was a TAC engineer years ago that we ultimately determined was in the switch configuration.
Not saying that's the case here, but you definitely need to rule that out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhoneBoy we have one VLAN migrated on firewall and it can't make https connection with WLC (WLC is not on firewall).
FW logs from PC to WLC IP show bypass and accept
Wireshark shows TCP Spurious Retransmission from source IP to the WLC IP
It also shows it using TLSv1 and not TLS v1.1 or v1.2
All other wireshark captures from valid connections show TLSv1.2
Please suggest if any input to fix the issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please create a new thread with the details of your situation.
This will include all versions/JHF in use, a network diagram CLEARLY showing source/destination for the traffic as well as any gateways involved, packet captures (with details where/how they were taken), and any other evidence you can provide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If that resolves your problem, look at mss clamping.
