Ask Your Question

TCP Reset Cisco 3850

asked 2019-04-04 20:54:02 +0000

cpocket gravatar image

Hello, (I would upload a pic or some files but I need 60 points I guess)

I'm having some communication issues between two PBXs. I setup a couple of laptops and captured at both ends. In going through capture I noticed something interesting. Please confirm if I'm reading this correctly and maybe help me understand what would cause this on the switch.

The source shows it’s coming from which is the phone server on the other side of my WAN which is I believe 4 hops away from When I look at the header it shows TTL 254 see second screenshot. This tells me this packet was only routed once. There’s no way it came from 4 hops away. So if you look at the mac address of the source you will see it’s 70:10:5C:De:75:f7 which is my core 3850 switch on that same subnet. To me the reset was produced by this SVI somehow. Maybe I’m wrong if so please explain how I’m wrong or explain how this is possible? The reverse is also true of the other capture the source of the reset shows it’s the IP of my phone server sitting on the subnet but looking at the reset packet itself the TTL is only 254 again so to me it looks like it’s being generated from the SVI on the 3850 in my Datacenter.

edit retag flag offensive close merge delete


You can post the capture files on a public share (Google Drive, Drop Box etc.) and then edit your question with a link to the files.

grahamb gravatar imagegrahamb ( 2019-04-04 21:12:15 +0000 )edit

1 Answer

Sort by » oldest newest most voted

answered 2019-04-07 22:33:12 +0000

SYN-bit gravatar image

If the IP TTL of the TCP/RST packet is 254, it is most likely not sent from the SVI of the 3850 switch, as it would have had an IP TTL of 64, 128 or 255. Assuming the packet was sent with a default IP TTL of either 64, 128 or 255, receiving it with an IP TTL of 254 means it was most likely sent by a device one hop upstream from the 3850.

My bet would be that it was a Loadbalancer or a Firewall that had a session timeout and therefor closed the connection to both sides with a TCP/RST.

edit flag offensive delete link more


Hello, thanks for the response. There is no FW, IPS or loadbalancer in between these two locations. This is all private metro e. Now maybe the provider has something that's causing this which I'm looking into. However, the router for these locations is more than 1 hop away. Due to this I is what leads me to the conclusion about the 3850. Cisco TAC thinks it's a timeout issue or like you said something in between but with such a short TTL my only thought is that switch. I'm by no means a WS expert so is it possible TTL could be incorrect in my capture?

cpocket gravatar imagecpocket ( 2019-04-08 19:15:22 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2019-04-04 20:54:02 +0000

Seen: 405 times

Last updated: Apr 07 '19