Ignored Unknown Record with TLSv1

asked 2018-10-22 22:11:51 +0000

jmorrowCoin gravatar image

Checked the Interweb, and haven't found a decent explanation on what the Wireshark SSL warning is for "Ignored Unknown Record". These are TLSv1 packets, most of them larger in size [ 2574 bytes 3834 bytes, or larger]. Downloading a 32M file from a server to a device. Most of the TLSv1 packets are listed as Application Data [TCP segment of a reassembled PDU], until we see a many large TLSv1 packets with Ignore Unknown Record in between TCP ACKs. Download does finish, but lots of DUP ACK and TCP Fast Retransmisisons. Test environment built across two datacenters via 200M MPLS.

Appreciate any advice.

edit retag flag offensive close merge delete