01-22-2023 02:45 PM - edited 01-22-2023 02:45 PM
Please view attached image.
x.20 is a DNS server.
x.52 is my workstation.
x.1 is the default gateway.
What is the most likely cause of this TCP retransmission flood of [FIN, ACK]s from the DNS server to my workstation?
Isn't the FIN, ACK the very end of the conversation?
Why would the DNS server keep sending these FIN, ACKs?
Thank you.
Solved! Go to Solution.
01-24-2023 10:24 AM
I run lab and as I guess from first time,
my lab R3 have default GW R1, I disable IP redirect in R1
R3 now connect to R4 (TCP traffic)
you can see many re-transmission,
so in your case you must solve Default GW and the issue will be solve.
01-22-2023 02:55 PM
why there is ICMP redirect ?
are you run HSRP or ASA HA ??
01-22-2023 03:26 PM - edited 01-22-2023 03:29 PM
Please standby.
01-22-2023 04:11 PM
I always standby captain. LoL..
anyway, why I ask about icmp redirect,
icmp redirect can cause if you have L3 device better than GW to forward the packet to destination.
if we can solve this issue, I think you will not see anymore TCP retransmission.
do traceroute and check if first hop is same or there are two hops appear ??
01-22-2023 04:54 PM - edited 01-23-2023 08:37 AM
Traceroute to DNS server...
1 <1 ms <1 ms <1 ms (! 9300 SwitchStack x4) This is x.x.x.1 (a vlan)
2 <1 ms <1 ms <1 ms (! 2960 router on same LAN= DMVPN)
3 10 ms 10 ms 10 ms (! 2951 DMVPN router at remote campus)
4 10 ms 10 ms 11 ms (! Nexus 9K at remote campus, HSRP)
5 10 ms 11 ms 10 ms (! x.x.x.20 DNS server)
01-23-2023 09:11 AM
This link is very helpful here...
01-24-2023 05:21 AM
If it helps, below is the traceroute from my workstation to the DNS server...
1 <1 ms <1 ms <1 ms (! 9300 SwitchStack x4) This is x.x.x.1 (a vlan)
2 <1 ms <1 ms <1 ms (! 2960 router on same LAN= DMVPN)
3 10 ms 10 ms 10 ms (! 2951 DMVPN router at remote campus)
4 10 ms 10 ms 11 ms (! Nexus 9K at remote campus, HSRP)
5 10 ms 11 ms 10 ms (! x.x.x.20 DNS server)
May you please help?
Thank you.
01-24-2023 10:24 AM
I run lab and as I guess from first time,
my lab R3 have default GW R1, I disable IP redirect in R1
R3 now connect to R4 (TCP traffic)
you can see many re-transmission,
so in your case you must solve Default GW and the issue will be solve.
01-25-2023 02:18 AM
Hello,
just out of curiosity, has this been resolved ? DMVPN issues often have to do with MTU size. If the issue still exists, post the DMVPN configs you are using at the hub and the spoke.
01-25-2023 05:42 AM
Thank you for your interest, Georg.
What commands would you like to see?
01-25-2023 10:39 AM
Hello,
so the issue is still there ? What I would need to see is the output of 'sh run' of both the DMVPN hub and spoke routers...
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: