<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireshark Traces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755781#M8636</link>
    <description>&lt;P&gt;Is this device connected to a ethernet switch?&lt;/P&gt;&lt;P&gt;If yes, you can configure a span port (port mirror) to this switch in order to capture the traffic destinated and originated to the 3G device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Nov 2018 12:54:55 GMT</pubDate>
    <dc:creator>Daniele Giordano</dc:creator>
    <dc:date>2018-11-30T12:54:55Z</dc:date>
    <item>
      <title>Wireshark Traces</title>
      <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755089#M8631</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know at which end the issue lies, In the&amp;nbsp; attached wireshark traces, the ip address 10.92.55.255 sends SYN to 92.60.106.204 and the ip 92.60.106.204 replies with SYN ACK but then we don't see any ACK from&amp;nbsp;&lt;SPAN&gt;10.92.55.255.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can we say the issue is at&amp;nbsp;10.92.55.255 end as its not replying back to the SYN ACk ? or is there anyway to check if&amp;nbsp;10.92.55.255 has received the SYN ACK from&amp;nbsp;92.60.106.204 so that it can respond&amp;nbsp;92.60.106.204 with an ACK ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wireshark Traces.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/25009i7548A37CD4231C45/image-size/large?v=v2&amp;amp;px=999" role="button" title="Wireshark Traces.JPG" alt="Wireshark Traces.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any help will be much appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755089#M8631</guid>
      <dc:creator>kamrannaseem1</dc:creator>
      <dc:date>2020-02-21T16:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark Traces</title>
      <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755169#M8632</link>
      <description>&lt;P&gt;Hi, yes the issue seems related to server with IP&amp;nbsp;&lt;SPAN&gt;10.92.55.255.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The ACK is missing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you install wireshark directly on the server?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If it's a linux, can you execute a tcpdump to check if the server receive the SYN ACK?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 14:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755169#M8632</guid>
      <dc:creator>Daniele Giordano</dc:creator>
      <dc:date>2018-11-29T14:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark Traces</title>
      <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755738#M8634</link>
      <description>&lt;P&gt;Thanks Daniele&lt;SPAN class=""&gt;&amp;nbsp;for the reply.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;10.92.55.255 device is a 3G device and the customer can't&amp;nbsp;run any debugs on it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there any other way we can check to see if the SYN ACK is being received by this device ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 11:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755738#M8634</guid>
      <dc:creator>kamrannaseem1</dc:creator>
      <dc:date>2018-11-30T11:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark Traces</title>
      <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755781#M8636</link>
      <description>&lt;P&gt;Is this device connected to a ethernet switch?&lt;/P&gt;&lt;P&gt;If yes, you can configure a span port (port mirror) to this switch in order to capture the traffic destinated and originated to the 3G device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 12:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755781#M8636</guid>
      <dc:creator>Daniele Giordano</dc:creator>
      <dc:date>2018-11-30T12:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark Traces</title>
      <link>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755788#M8638</link>
      <description>&lt;P&gt;3G is a wireless radio connection type. So it would not be connected to a wired switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best the OP would be able to do is monitor from the point at which it leaves the network and goes to the wireless gateway. You may be able to see the SYN ACK outbound there; but the only way to see if for sure on the endpoint is to have an on-device tool that captures endpoint traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 13:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireshark-traces/m-p/3755788#M8638</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-11-30T13:09:26Z</dc:date>
    </item>
  </channel>
</rss>

