very low TCP RTOs
Hi there, i'm new to the wireshark community and looking for some help.
Since a few weeks, users in my company are complaining about slow SSH connections to linux servers. They work from a distant network ( MPLS or VPN). The whole infrastructure (servers & switching) is in a datacenter, carried by some Nexus 5000 and Nexus 2000 with multiples Vlans. The routing is managed by an old fortigate F1240B, which has not been updated since v5.0
After capturing some traffic, I see that I get a huge amount of TCP retransmission, and not only for SSH connections. Looking deep into the tcp frames, I see that the initial RTO is between 1 and 5 µS which looks very low.
Are such RTO normal ? If no, what can cause this and how can I solve this problem ?
Any help would be appreciated. I searched hours on the web but could find any answers..
As I understand, RTOs are defined by TCP and not applications or OS ?
If you can anonymize a capture with something like TraceWrangler or one of the tools here, post it to a public file sharing site like Google, Onedrive, S3,... then update your question with a link to the file.
Please find the capture here :
http://dl.free.fr/getfile.pl?file=/kR...