retransmission the incorrect seq

asked 2019-08-22 04:57:57 +0000

GoBook gravatar image

the wireshark caputure image link

please explain why the retransmisstion begin with seq 9388, it was weird.

edit retag flag offensive close merge delete


There are more weird things in this capture, but helping you analyze this issue is not really because:

  • The capture was made on the webserver which has TCP segmentation offloading on. This means the packets in the trace are not exactly the packets on the network.
  • You provided a screenshot instead of a capture file, this means most of the interesting fields are not available.

Could you please make another capture on a span-port towards the server? Anonimize it with TraceWrangler and then post it on a public fileshare like DropBox, OneDrive, etc for us to have a look at?

SYN-bit gravatar imageSYN-bit ( 2019-08-23 07:49:26 +0000 )edit