Hi Guys,
Good day. User PC (which is on sleep mode) trigger NDL AAS (3128) and access to Proxy server and caused high bandwidth usage.
From wireshark packet capture, the flow is something like this :-
Source Destination Protocol Length Info
User Proxy TCP 60 ndl-ass [ACK]
Proxy User HTTP 1314 Continuation or non-HTTP traffic
Proxy User HTTP 1314 Continuation or non-HTTP traffic
Proxy User HTTP 1314 [TCP out-of-order] Continuation or non-HTTP traffic
Proxy User HTTP 1314 [TCP Retransmission] Continuation or non-HTTP traffic . <keep repeating="" the="" same="" packet="">
Did you guys have any idea ? Why the user will trigger the connection in sleep mode or AFK mode ?
Thanks.