cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
1
Helpful
4
Replies

not showing SYN and SYN-ACK in Wireshark

ankitohc
Spotlight
Spotlight

Hello Expert,

We have internal application which is fetching the data from window server using mapped if drive is not mapped then application won't work so when i trace the packets and select the source client and dst server. I dont see SYN, SYN-ACK packets i see only ACK.

Why I am not seeing the SYN, SYN-ACK in the wirehshark trace files.

 

ankitohc_0-1715695381078.png

 

4 Replies 4

no problem, I think you start capture traffic after tcp 3-way handshake 

MHM

I thought the same , Network Drive is already mapped on the client so that means if drive is mapped and data is fetching from the drives itself then it shows traffic after tcp 3-way handshake


How does it work with SMB?

 

I guess Once a network drive is mapped, and the SMB session is established, Wireshark will typically not capture the SYN, SYN-ACK, packets again for subsequent interactions with that mapped drive.

Yes you are correct'

Try close session by apply acl abd drop traffic to port 445 and then remove the acl' 

Sure you will see new tcp 3way for new session.

MHM

Review Cisco Networking for a $25 gift card