11-29-2012 05:07 PM - edited 03-07-2019 10:19 AM
I am trying to track down an application response problem on my network (the traffic goes through a 6509 and FWSM).
I noticed in one of my WireShark captures, that the client at times seems to be sending ackowledgements (ACKs) over and over again, and I'm not sure if this indicates a problem/retransmission.
TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489559129, Win=65535 |
and then repeats
Basically, a web server is delivering images to the client, but end users are complaining of slowness and freezes.
WireShark has not flagged this as a problem (comes up "green")
any advice would be great
11-29-2012 06:20 PM
Well,
client is sending different acknowledgments for some small packets. It seems TCP window (seems to be 2760) provided by server is small and client can't send single acnowledgment for all these packets.
You need to check with server team why this windown is so smalle and if there is a chance to increase it.
Nik
11-29-2012 07:23 PM
Nikolay:
Maybe some more details will help
Here is another look
63.29288 | 172.25.87.10 | 192.168.151.25 | TCP | TCP:[Continuation to #982]Flags=...AP..., SrcPort=HTTP(80), DstPort=2667, PayloadLen=572, Seq=1489574309 - 1489574881, Ack=1719591657, Win=64499 | ||||
63.29301 | 172.25.87.10 | 192.168.151.25 | HTTP | HTTP:HTTP Payload, URL: /route/file | ||||
63.32718 | 192.168.151.25 | 172.25.87.10 | TCP | TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489559129, Win=65535 | ||||
63.32773 | 192.168.151.25 | 172.25.87.10 | TCP | TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489561889, Win=65535 | ||||
63.32825 | 192.168.151.25 | 172.25.87.10 | TCP | TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489564649, Win=65535 | ||||
63.32876 | 192.168.151.25 | 172.25.87.10 | TCP | TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489567409, Win=65535 | ||||
63.3293 | 192.168.151.25 | 172.25.87.10 | TCP | TCP:Flags=...A...., SrcPort=2667, DstPort=HTTP(80), PayloadLen=0, Seq=1719591657, Ack=1489570169, Win=65535 |
so is the window size are talking about the "SrcPort=2667" above? How does that relate to
Win=65535 ?
It look like the server is pushing data back to the client here, but all the ACKs have me worried.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: