Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

I'm assuming 10.118.1.201 is the client, as it makes a new connection to 10.3.213.15 in frame 9205. Before that, it killed the previous connection on port 50000 by sending a TCP RST in frame 8721. Why it was sending the TCP RST can not be read from the packet capture file. From the capture point of view, it is the client that resetted the connection and then opened a new one 3 minutes later.

You could look into the application logs if there are any. Maybe a debug llog level can be chosen to increase the logging.