RST, ACK Server to Host

asked 2021-10-05 21:14:49 +0000

Hello, I am new to these forums.

I have the following situation, a communication is being generated between a server with IP 172.16.10.12 (port 50500) and a host 172.30.2.11, the communication in some moments is interrupted and the application stops working, it has been detected in the capture that the server sends the RST and ACK flag, from one moment to another the application starts working, it is important to mention that the traffic passes through a fortinet UTM.

I attach the screenshot, could you please give me some clue of what may be happening.

https://drive.google.com/file/d/1_Ar0...

Thank you very much.

Ricardo

edit retag flag offensive close merge delete

Comments

What device did the packet capture?

Chuckc gravatar imageChuckc ( 2021-10-06 00:40:48 +0000 )edit

Hi, the capture was done on the Fortinet UTM, physically the server (172.16.10.12) is behind the UTM.

Thank you

jmartie gravatar imagejmartie ( 2021-10-06 16:16:14 +0000 )edit