Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] [TCP Previous segemnt lost] Ignored Unknown record

From: jacob c <jctx09@xxxxxxxxx>
Date: Thu, 29 May 2008 06:51:08 -0700 (PDT)
Sake,
 
Thank you for the response. It does seem like whenever a packet gets dropped and the LB (BigIP) sees a quite time of 6 to 8 seconds, it sends a FIN to the client. Apparently, the behavior is very similar when going to the webserver itself. I'm trying to come up with a custom tcp profile to solve this but it still seems odd for either OS to close out the session because of quiet time of 6 or more seconds.
 
Thanks,

Sake Blok <sake@xxxxxxxxxx> wrote:
On Tue, May 27, 2008 at 04:22:16PM -0700, jacob c wrote:
>
> We have a device that talks to a server through a load balancer.
> The load balancer is a full proxy. When this intermittent problem
> happens, the only difference I see between a good trace and a "bad"
> trace/transaction is multiple FIN packets sent from the load
> balancer before the transaction is complete. These are not being
> forward form the webserver on the backend. In this example, these
> packets are 257 - 263. Any insight as to what is causing them would
> be helpful.

It looks like your load balancer has a session timeout on the client
side. What kind of load balancer do you use? Have a look at all the
settings, especially to any tcp settings.

> I have attached the trace in text format.

Next time, please provide a trace in binary format, they are usually
about the same size as the text format, but give a whole lot more
information. And it makes helping you a lot easier, as we can use
our favorite tool to read it :-)

Cheers,
Sake
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users