back to back to back...ACKs with no SYN,ACK response
I am troubleshooting your typical "slow network connection". Two devices seem to be trying to perform the TLS handshake but neither is responding with a SYN. I wouldn't even consider myself a "noob" at WireShark. What is below a "noob"? I've got one device, 10.12.10.12 sending an ACK to 10.3.20.120 in Frame 1. In Frame 2 I have 10.3.20.120 sending a PSH,ACK to 10.12.10.12. In Frame 3 I have 10.3.20.120 sending another PSH,ACK to 10.12.10.12. In Frame 4 I have 10.12.10.12 sending an ACK to 10.3.20.120. In Frame 5 10.12.10.12 is sending another ACK to 10.3.20.120. And finally in Frame 6 10.3.20.120 is sending a PSH,ACK to 10.12.10.12.
I tried to upload the pcap file but I am also new to this community and when I tried to upload I was told that I need >60 pts to upload files...
SYN is never a response. It is the opening of a conversation. Based on the description of the packets there is however nothing wrong with them. Just 2 machines having a conversation.
First describe in more detail the problem you are experiencing. Just how the user sees the problem.
The user is complaining about slow internet connectivity. Again this is a dispatch call center for a state department. The customer stated that when call volume is high that the computers connected to the phones slow down considerably. Every department uses a VoIP phone where the phone is basically a switch.
I though the 3-way handshake was machine 1 sending an ACK to machine 2 and machine 2 responding with a SYN-ACK and then machine 1 finishing the handshake with a FIN-ACK. I will have to go back refresh my memory on TLS.
A capture can be added to a public share and a link to it can be added back here.
public share?
Something like Google Drive, DropBox etc.