Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] (no subject)

From: D W <servnj@xxxxxxxxxxx>
Date: Thu, 30 Apr 2009 17:18:46 -0400

I have 3 windows 2003 terminal servers setup for load balance. IP addresses 192.168.1.14, 192.168.1.15, 192.168.1.16 Cluster IP 192.168.1.40 multicast. 

I have a remote site connected via site to site VPN tunnel using Cisco ASA devices, subnet 192.168.100.1. On the local LAN I can get connected to terminal servers using the cluster IP, at the remote site I can not. At

I have setup wireshark on my 192.168.1.0 subnet and setup a packet capture on the ASA5510. On the wireshark I see SYN packets coming in from my machine 192.168.100.102 to the cluster IP and I see SYN,ACK packets Src the cluster IP with the mac address of one of the terminal servers and the dst my IP address with the mac address of the ASA 5510. On the ASA5510 packet capture I only see the SYN packets from my machine coming in but no SYN,ACK packets going out. What  do I do to find out what happened to the SYN,ACK packets?

I did a packet capture when connecting to the actual IP address of the terminal server (Which Works)  and compared the SYN,ACK packets from both and saw no difference.



Windows Live™ Hotmail®:…more than just e-mail. Check it out.