Diagnosing a port

Windows Server 2019 standard

Port: 50001

Complaint: Network; is set up Hub and Spoke to multiple stores, data travels bi-directionally from the Hub and the spokes (servers). Application utilizing this connection errors out (intermittently) stating that port 50001 is in use.

Traffic is IPSEC tunnels. Traffic considered internal traffic.

Firewall on server(s) is disabled

I have installed wireshark and am doing a capture specific to port 50001, not seeing any hard errors, or rejections.

Any ideas on how I could monitor this port, and isolate an error that could cause this problem? Sorry not a lot to go off of, basically all the information I have, application not connecting due to port 50001 in use. I don't see anything except that application accessing port 50001.

I don't know a lot about Wireshark so looking for help\guidance.

Can add describe the protocol stack? Is it using ESP, TLS, or proprietary L3/L4 encryption?

BigFatCat gravatar imageBigFatCat ( 2021-06-02 19:29:23 +0000 )edit

Looks like it is using TLS

TecDragon gravatar imageTecDragon ( 2021-06-02 19:40:30 +0000 )edit

Is there a specific client that is chronically having issues? What network access is available for monitoring traffic? If this is TCP TLS, troubleshooting TCP will help isolate the issue.

BigFatCat gravatar imageBigFatCat ( 2021-06-04 12:52:47 +0000 )edit