Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Intermittant Machine Lockup through proxy to Internet

From: "Sheahan, John" <John.Sheahan@xxxxxxxxxxxxx>
Date: Fri, 13 Nov 2009 19:59:57 -0500
I have been plagued with intermittent reported problems from end users who say their machines will lockup occasionally when going to the internet.

In the trace attached, all the proxy traffic is on port 8080 from one machine (76.11). 

If you look at just the conversation on port 4918, everything appears to be going along fine until for some reason, the client (76.11) reports a "TCP Zero Window" and then 11 seconds go by before the client resets the connection..not sure what would cause this.did the client run out of resources?

 Then the client goes to Google and gets some data but the next two GETS return "HTTP 204 No Content".

The client then tries to go to yahoo.com, gets redirected (packet 449) and appears to pull down quite a bit of data but when I look at the HTML data in packet 611, there is only one line of text.

In packet 781, the client tries to go to cnn.com and gets an "HTTP 304 Not Modified" then the client FINs out the connection.

What I do notice though is that all HTTP GETS are sent from the client using HTTP 1.1 and the proxy always answers back with HTTP 1.0 responses.could this be the problem?

Shouldn't the proxy talk back on HTTP 1.1 if a request is made using HTTP 1.1 from the client?

Thanks

jack

Attachment: port-8080.pcap
Description: port-8080.pcap