Specific website loading slow, can my wireshark log help?
Since moving from europe to asia, I have sometimes have problems connecting to a specific website, which I have to access regularly.
The problem seems to be on my side (probably router/IPS problem), since the website works normal for other users from europe, but I have problems from asia (chrome gives me the error "err_connection_reset" and the website stops loading)
I tried many things already, but cannot find a solution so far.
Here is the log: [removed]
P.S. the first 6 packages can be ignored, since they were from a previous capture and I don't know how to remove them!
EDIT:
mtupath shows the following:
MTU path scan to agenturtipp.de (85.13.165.58), ttl=64, limit=48
26 best MSS 1024 (estimated MTU 1052) [pPPPP*ppppppppppP**P**P***]
#1 MSS IN RANGE 1 <== 1023 ==> 1024
#2 SCAN TIMEOUT 1025 <== 439 ==> 1464
#3 MSS EXCEEDED 1465 <== 14919 ==> 16384
[WARNING] Possible PMTU blackhole in route to peer
Thank you !
Edit 30th April:
The problem still occurs after setting lower MTU :( Here is a new anonymized wireshark log: https://we.tl/t-72S99n4PHf
MTU settings in cmd: https://i.imgur.com/Aa3u2wC.jpeg
MTU settings in my router cannot be set to 1052: https://i.imgur.com/HysrxIA.jpeg Do you think that might affect the MTU settings I set in the cmd? Or should the cmd setting be enought?
Edit 1st May: mtr to the server:
|------------------------------------------------------------------------------------------|
| WinMTR statistics |
| Host - % | Sent | Recv | Best | Avrg | Wrst | Last |
|------------------------------------------------|------|------|------|------|------|------|
| 192.168.1.1 - 0 | 893 | 893 | 0 | 0 | 9 | 0 |
| h254.s98.ts.hinet.net - 0 | 893 | 893 | 0 | 1 | 10 | 2 |
| 168-95-162-94.tpn2-3301.hinet.net - 0 | 893 | 893 | 0 | 2 | 38 | 2 |
| 220-128-9-54.tpdb-3031.hinet.net - 16 | 555 | 470 | 1 | 2 | 12 | 1 |
| 220-128-13-93.r4102-s2.tp.hinet.net - 1 | 889 | 888 | 1 | 2 | 43 | 2 |
| 220-128-6-109.r4002-s2.tp.hinet.net - 0 | 893 | 893 | 0 | 3 | 86 | 8 |
| 202-39-91-29.pa-r32.us.hinet.net - 0 | 893 | 893 | 134 | 136 | 192 | 138 |
| 202-39-84-29.pa-r31.us.hinet.net - 0 | 893 | 893 | 134 | 136 | 176 | 140 |
| 4.7.18.145 - 100 | 180 | 1 | 0 | 137 | 137 | 137 |
| ae2.3603.edge4.ber1.neo.colt.net - 0 | 893 | 893 | 280 | 282 | 306 | 281 |
| NEUE-MEDIEN.edge4.Berlin1.Level3.net - 0 | 893 | 893 | 286 | 288 | 327 | 287 |
| dd49318.kasserver.com - 0 | 893 | 893 | 282 | 283 | 294 | 284 |
|________________________________________________|______|______|______|______|______|______|
WinMTR v0.92 GPL V2 by Appnor MSP - Fully Managed Hosting & Cloud Provider
4.7.18.145 seems to lose all packets. A MTU scan and pinging seems to work fine though:
MTU path scan to 4.7.18.145, ttl=64, limit=48
# 16 processing - best MSS 1024 (estimated MTU 1052) [pPPPPPpppppppppp]
# 01 nearest minimum MTU on local interface
#1 MSS IN RANGE 1 <== 1023 ==> 1024
#2 MSS EXCEEDED 1025 <== 15359 ==> 16384
ping 4.7.18.145
Ping wird ausgeführt für 4.7.18.145 mit 32 Bytes Daten:
Antwort von 4.7.18 ...
Could you please share the file in PCAP or PCAPNG format instead of text output, we love using Wireshark for a reason ;-)
Oh yeah, my bad. I anonymized it: https://we.tl/t-IPz3lxhrDM Thank you!
Thanks for adding the link to the pcapng file!