TCP DUP ACK and TCP Spurious Transmissions
can someone please analyze this pcap file and tell me why in the world there are so many TCP DUP and Spurious transmissions.
can someone please analyze this pcap file and tell me why in the world there are so many TCP DUP and Spurious transmissions.
Hey Wireshark People!!
We have a PC onsite that send OPC DA data over our network back to a windows box at our main site. The meraki S2S vpn is looking healthy and other devices onsite are working fine. Windows\mapped drives etc
The data is reported to a scada dashboard that give the enginees an easy to use system to monitor the engines . This connection keeps dropping. The meraki is working fine. no link flaps. VPN disconnects / reconnects. (ping path ping and Nmap connect from the server to the machine) I believe this issue is the machine. I can ping it ok and can vnc to it but is very slow i mean antiquated. its a Win 2k box!!
From the wireshark file we are seeing alot of Dup ack and re-transmissons 119 34.917119 10.32.0.151 180.1.4.41 TCP 1446 [TCP Retransmission] 38080 → 26254 [ACK] Seq=359 Ack=3831 Win=65535 Len=1392 124 43.729276 10.32.0.151 180.1.4.41 TCP 1446 [TCP Retransmission] 38080 → 26254 [ACK] Seq=359 Ack=3859 Win=65507 Len=1392
I was wondering if you guys could give any insight as to what this could be
The pc onsite is connect to the meraki via a HP Procurve. This has no Vlans so a flat network. Tomorrow i am going to check the procurve interface to see if there are any runts, collision errors, fcs errors etc
Any assistance you could give i would be very grateful!
Regards
Daniel Schindler
Jack of all trades and eternal Optimist
Please start posting anonymously - your entry will be published after you log in or create a new account.
Asked: 2018-02-12 20:16:27 +0000
Seen: 531 times
Last updated: Feb 12 '18
what happened to the network?(from a noob)
Low throughput between vmWare hosts in vxlan topology - spurious retransmissions.
What is TCP Previous segment / Out-of-order / TCP Dup ACK
Reason for TCP spurious retransmission
loads of TCP Retransmission, TCP Out-Of-Order, TCP Dups
I think due to packet loss...
Could this all be caused because I am sniffing a hub?