<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP RESET-ACK message without RESET in Capture. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963396#M401987</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am having a problem with communication between two machines, i have put the packet capture and following is the output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;61: 09:09:25.821628 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: S 2228708690:2228708690(0) win 5840 &amp;lt;mss 1460,sackOK,timestamp 8266666 0,nop,wscale 6&amp;gt; &lt;/P&gt;&lt;P&gt;65: 09:09:25.823596 802.1Q vlan#726 P0 192.168.249.21.2052 &amp;gt; 192.168.249.69.731: S 1457523457:1457523457(0) ack 2228708691 win 5840 &amp;lt;mss 1380&amp;gt; &lt;/P&gt;&lt;P&gt;66: 09:09:25.823764 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: . ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;67: 09:09:25.823794 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: P 2228708691:2228708735(44) ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;68: 09:09:28.813388 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: P 2228708691:2228708735(44) ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;69: 09:09:33.026732 802.1Q vlan#726 P0 192.168.249.21.2052 &amp;gt; 192.168.249.69.731: R 1457523458:1457523458(0) ack 2228708691 win 5840&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;The first three packets are three-way handshake and then 2 data packets but both are same packets and i think it is a repeated packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last packet is TCP-Reset-Ack but i can't see TCP-Reset packet in capture, is it something to do with 2 repeated data packets or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad Hashim.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:31:42 GMT</pubDate>
    <dc:creator>Amjad Hashim</dc:creator>
    <dc:date>2019-03-11T23:31:42Z</dc:date>
    <item>
      <title>TCP RESET-ACK message without RESET in Capture.</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963396#M401987</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am having a problem with communication between two machines, i have put the packet capture and following is the output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;61: 09:09:25.821628 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: S 2228708690:2228708690(0) win 5840 &amp;lt;mss 1460,sackOK,timestamp 8266666 0,nop,wscale 6&amp;gt; &lt;/P&gt;&lt;P&gt;65: 09:09:25.823596 802.1Q vlan#726 P0 192.168.249.21.2052 &amp;gt; 192.168.249.69.731: S 1457523457:1457523457(0) ack 2228708691 win 5840 &amp;lt;mss 1380&amp;gt; &lt;/P&gt;&lt;P&gt;66: 09:09:25.823764 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: . ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;67: 09:09:25.823794 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: P 2228708691:2228708735(44) ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;68: 09:09:28.813388 802.1Q vlan#726 P0 192.168.249.69.731 &amp;gt; 192.168.249.21.2052: P 2228708691:2228708735(44) ack 1457523458 win 5840 &lt;/P&gt;&lt;P&gt;69: 09:09:33.026732 802.1Q vlan#726 P0 192.168.249.21.2052 &amp;gt; 192.168.249.69.731: R 1457523458:1457523458(0) ack 2228708691 win 5840&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;The first three packets are three-way handshake and then 2 data packets but both are same packets and i think it is a repeated packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last packet is TCP-Reset-Ack but i can't see TCP-Reset packet in capture, is it something to do with 2 repeated data packets or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad Hashim.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963396#M401987</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2019-03-11T23:31:42Z</dc:date>
    </item>
    <item>
      <title>TCP RESET-ACK message without RESET in Capture.</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963397#M401988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;From the captures, it seems that 192.168.249.21 is sending the RESET? Who is 192.168.249.21? a client or the server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 15:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963397#M401988</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-17T15:38:54Z</dc:date>
    </item>
    <item>
      <title>TCP RESET-ACK message without RESET in Capture.</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963398#M401989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ramraj,&lt;/P&gt;&lt;P&gt;Thanks for reply, .69 is a server and .21 is backup appliance. If u read carefully you will find that it is Reset ACK packet rather than Reset.&lt;/P&gt;&lt;P&gt;The problem is i could not see the reset packet at all and Reset ACK comes in, don't know what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am struggling with it for a while and need to resolve it as soon as possible. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 16:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963398#M401989</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-17T16:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: TCP RESET-ACK message without RESET in Capture.</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963399#M401990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;This is my understanding with regards to your above packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;61: 192.168.249.69 sends SYN to 192.168.249.21&lt;/P&gt;&lt;P&gt;65: 192.168.249.21 sends SYN ACK to 192.168.249.69&lt;/P&gt;&lt;P&gt;66: 192.168.249.69 sends ACK to 192.168.249.21&lt;/P&gt;&lt;P&gt;67: 192.168.249.69 sends a PUSH to 192.168.249.21 (data/payload transfer)&lt;/P&gt;&lt;P&gt;68: 192.168.249.69 sends a PUSH to 192.168.249.21 (DUPLICATE PACKET BECAUSE 67 AND 68 IS THE SAME THING, same packet size!!)&lt;/P&gt;&lt;P&gt;69: 192.168.249.21 sends a RESET to 192.168.249.69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: &lt;/P&gt;&lt;P&gt;65: TCP Sequence Number = 1457523457&lt;/P&gt;&lt;P&gt;66: TCP Sequence Number = 1457523458&lt;/P&gt;&lt;P&gt;67: TCP Sequence Number = 1457523458&lt;/P&gt;&lt;P&gt;68: TCP Sequence Number = 1457523458&lt;/P&gt;&lt;P&gt;69: TCP Sequence Number = 1457523458&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question here should be why is your backup appliance sending a RESET to the server? I guess you'll need to check with the backup appliance vendor/principal on this. Just out of curiousity, if your backup appliance and the server were in the same network address, no Cisco ASA FW in between, will this work fine?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 03:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963399#M401990</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-18T03:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: TCP RESET-ACK message without RESET in Capture.</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963400#M401991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bro,&lt;/P&gt;&lt;P&gt;You are abosolutely right about duplicate packet, see the packet 69 below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;69: 09:09:33.026732 802.1Q vlan#726 P0 192.168.249.21.2052 &amp;gt; 192.168.249.69.731: &lt;STRONG&gt;R &lt;/STRONG&gt;1457523458:1457523458(0) &lt;STRONG&gt;ack&lt;/STRONG&gt; 2228708691 win 5840&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is reset-acknowledgement that .21 is sending, i was in touch with vendor and they said the same thing. I hope this will help understand the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 09:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-ack-message-without-reset-in-capture/m-p/1963400#M401991</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-18T09:57:34Z</dc:date>
    </item>
  </channel>
</rss>

