Wireshark-users: [Wireshark-users] Help - TCP Previous segment lost
From: "Fabricio Oliveira" <fabriciooli@xxxxxxxxx>
Date: Wed, 7 Nov 2007 09:35:39 -0300
Hi,
I am having the same problem found in the list, but not found a definitive solution, someone help me?
"[TCP Previous segment lost]"
"[A segment before this frame was lost]"
The next review of the packages!!!
=========================================================================================================
No. Time Source Destination Protocol Info
10508 2007-11-05 06:28:22.657633 169.254.54.49 169.254.255.255 BROWSER Local Master Announcement JDDP, Workstation, Server, NT Workstation, Potential Browser, Master Browser
Frame 10508 (243 bytes on wire, 243 bytes captured)
Ethernet II, Src: Netronix_45:b4:24 (00:08:54:45:b4:24), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
Internet Protocol, Src: 169.254.54.49 (169.254.54.49), Dst: 169.254.255.255 (169.254.255.255)
User Datagram Protocol, Src Port: netbios-dgm (138), Dst Port: netbios-dgm (138)
NetBIOS Datagram Service
SMB (Server Message Block Protocol)
SMB MailSlot Protocol
Microsoft Windows Browser Protocol
0000 ff ff ff ff ff ff 00 08 54 45 b4 24 08 00 45 00 ........TE.$..E.
0010 00 e5 26 8d 00 00 80 11 89 4d a9 fe 36 31 a9 fe ..&......M..61..
0020 ff ff 00 8a 00 8a 00 d1 86 89 11 0e ae 75 a9 fe .............u..
0030 36 31 00 8a 00 bb 00 00 20 45 4b 45 45 45 45 46 61...... EKEEEEF
0040 41 43 41 43 41 43 41 43 41 43 41 43 41 43 41 43 ACACACACACACACAC
0050 41 43 41 43 41 43 41 43 41 00 20 45 48 46 43 46 ACACACACA. EHFCF
0060 46 46 41 45 50 43 41 43 41 43 41 43 41 43 41 43 FFAEPCACACACACAC
0070 41 43 41 43 41 43 41 43 41 42 4f 00 ff 53 4d 42 ACACACACABO..SMB
0080 25 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 %...............
0090 00 00 00 00 00 00 00 00 00 00 00 00 11 00 00 21 ...............!
00a0 00 00 00 00 00 00 00 00 00 e8 03 00 00 00 00 00 ................
00b0 00 00 00 21 00 56 00 03 00 01 00 00 00 02 00 32 ...!.V.........2
00c0 00 5c 4d 41 49 4c 53 4c 4f 54 5c 42 52 4f 57 53 .\MAILSLOT\BROWS
00d0 45 00 0f 00 80 fc 0a 00 4a 44 44 50 00 00 00 00 E.......JDDP....
00e0 00 00 00 00 00 00 00 00 05 00 03 10 05 00 0f 01 ................
00f0 55 aa 00 U..
=========================================================================================================
No. Time Source Destination Protocol Info
10509 2007-11-05 06:29:18.814324 10.5.5.15 10.4.20.17 MQ [TCP Previous segment lost] 1414 > 1820 [PSH, ACK] Seq=1250112 Ack=1256240 Win=33580 Len=216 | MQOPEN_REPLY Obj=QL.REP.60934221.04902979.01
Frame 10509 (270 bytes on wire, 270 bytes captured)
Ethernet II, Src: 10.4.20.1 (00:0d:88:ef:7c:ee), Dst: MS-NLB-VirtServer_0a:04:14:13 (02:bf:0a:04:14:13)
Internet Protocol, Src: 10.5.5.15 ( 10.5.5.15), Dst: 10.4.20.17 ( 10.4.20.17)
Transmission Control Protocol, Src Port: 1414 (1414), Dst Port: 1820 (1820), Seq: 1250112, Ack: 1256240, Len: 216
Source port: 1414 (1414)
Destination port: 1820 (1820)
Sequence number: 1250112 (relative sequence number)
[Next sequence number: 1250328 (relative sequence number)]
Acknowledgement number: 1256240 (relative ack number)
Header length: 20 bytes
Flags: 0x18 (PSH, ACK)
Window size: 33580
Checksum: 0x9569 [correct]
[SEQ/ACK analysis]
[TCP Analysis Flags]
[A segment before this frame was lost]
[PDU Size: 216]
WebSphere MQ (MQOPEN_REPLY)
0000 02 bf 0a 04 14 13 00 0d 88 ef 7c ee 08 00 45 00 ..........|...E.
0010 01 00 96 0a 40 00 40 06 76 c5 0a 05 05 0f 0a 04 ....@.@.v.......
0020 14 11 05 86 07 1c f4 e8 86 8a 29 5d ab 50 50 18 ..........)].PP.
0030 83 2c 95 69 00 00 54 53 48 20 00 00 00 d8 02 93 .,.i..TSH ......
0040 30 00 00 00 00 00 00 00 00 00 22 02 00 00 b5 01 0.........".....
0050 00 00 00 00 00 d8 00 00 00 00 00 00 00 00 a0 04 ................
0060 e0 f3 4f 44 20 20 01 00 00 00 01 00 00 00 51 4c ..OD ........QL
0070 2e 52 45 50 2e 36 30 39 33 34 32 32 31 2e 30 34 .REP.60934221.04
0080 39 30 32 39 37 39 2e 30 31 00 00 00 00 00 00 00 902979.01..... . .
0090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 51 4d ..............QM
00a0 2e 30 34 39 30 32 39 37 39 2e 30 31 00 00 00 00 .04902979.01....
00b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 .............. .
00d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4d 55 ..............MU
0100 53 52 5f 4d 51 41 44 4d 49 4e 01 10 00 00 SR_MQADMIN....
Thanks,
Fabricio Oliveira
(91)-8112-1932
I am having the same problem found in the list, but not found a definitive solution, someone help me?
"[TCP Previous segment lost]"
"[A segment before this frame was lost]"
The next review of the packages!!!
=========================================================================================================
No. Time Source Destination Protocol Info
10508 2007-11-05 06:28:22.657633 169.254.54.49 169.254.255.255 BROWSER Local Master Announcement JDDP, Workstation, Server, NT Workstation, Potential Browser, Master Browser
Frame 10508 (243 bytes on wire, 243 bytes captured)
Ethernet II, Src: Netronix_45:b4:24 (00:08:54:45:b4:24), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
Internet Protocol, Src: 169.254.54.49 (169.254.54.49), Dst: 169.254.255.255 (169.254.255.255)
User Datagram Protocol, Src Port: netbios-dgm (138), Dst Port: netbios-dgm (138)
NetBIOS Datagram Service
SMB (Server Message Block Protocol)
SMB MailSlot Protocol
Microsoft Windows Browser Protocol
0000 ff ff ff ff ff ff 00 08 54 45 b4 24 08 00 45 00 ........TE.$..E.
0010 00 e5 26 8d 00 00 80 11 89 4d a9 fe 36 31 a9 fe ..&......M..61..
0020 ff ff 00 8a 00 8a 00 d1 86 89 11 0e ae 75 a9 fe .............u..
0030 36 31 00 8a 00 bb 00 00 20 45 4b 45 45 45 45 46 61...... EKEEEEF
0040 41 43 41 43 41 43 41 43 41 43 41 43 41 43 41 43 ACACACACACACACAC
0050 41 43 41 43 41 43 41 43 41 00 20 45 48 46 43 46 ACACACACA. EHFCF
0060 46 46 41 45 50 43 41 43 41 43 41 43 41 43 41 43 FFAEPCACACACACAC
0070 41 43 41 43 41 43 41 43 41 42 4f 00 ff 53 4d 42 ACACACACABO..SMB
0080 25 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 %...............
0090 00 00 00 00 00 00 00 00 00 00 00 00 11 00 00 21 ...............!
00a0 00 00 00 00 00 00 00 00 00 e8 03 00 00 00 00 00 ................
00b0 00 00 00 21 00 56 00 03 00 01 00 00 00 02 00 32 ...!.V.........2
00c0 00 5c 4d 41 49 4c 53 4c 4f 54 5c 42 52 4f 57 53 .\MAILSLOT\BROWS
00d0 45 00 0f 00 80 fc 0a 00 4a 44 44 50 00 00 00 00 E.......JDDP....
00e0 00 00 00 00 00 00 00 00 05 00 03 10 05 00 0f 01 ................
00f0 55 aa 00 U..
=========================================================================================================
No. Time Source Destination Protocol Info
10509 2007-11-05 06:29:18.814324 10.5.5.15 10.4.20.17 MQ [TCP Previous segment lost] 1414 > 1820 [PSH, ACK] Seq=1250112 Ack=1256240 Win=33580 Len=216 | MQOPEN_REPLY Obj=QL.REP.60934221.04902979.01
Frame 10509 (270 bytes on wire, 270 bytes captured)
Ethernet II, Src: 10.4.20.1 (00:0d:88:ef:7c:ee), Dst: MS-NLB-VirtServer_0a:04:14:13 (02:bf:0a:04:14:13)
Internet Protocol, Src: 10.5.5.15 ( 10.5.5.15), Dst: 10.4.20.17 ( 10.4.20.17)
Transmission Control Protocol, Src Port: 1414 (1414), Dst Port: 1820 (1820), Seq: 1250112, Ack: 1256240, Len: 216
Source port: 1414 (1414)
Destination port: 1820 (1820)
Sequence number: 1250112 (relative sequence number)
[Next sequence number: 1250328 (relative sequence number)]
Acknowledgement number: 1256240 (relative ack number)
Header length: 20 bytes
Flags: 0x18 (PSH, ACK)
Window size: 33580
Checksum: 0x9569 [correct]
[SEQ/ACK analysis]
[TCP Analysis Flags]
[A segment before this frame was lost]
[PDU Size: 216]
WebSphere MQ (MQOPEN_REPLY)
0000 02 bf 0a 04 14 13 00 0d 88 ef 7c ee 08 00 45 00 ..........|...E.
0010 01 00 96 0a 40 00 40 06 76 c5 0a 05 05 0f 0a 04 ....@.@.v.......
0020 14 11 05 86 07 1c f4 e8 86 8a 29 5d ab 50 50 18 ..........)].PP.
0030 83 2c 95 69 00 00 54 53 48 20 00 00 00 d8 02 93 .,.i..TSH ......
0040 30 00 00 00 00 00 00 00 00 00 22 02 00 00 b5 01 0.........".....
0050 00 00 00 00 00 d8 00 00 00 00 00 00 00 00 a0 04 ................
0060 e0 f3 4f 44 20 20 01 00 00 00 01 00 00 00 51 4c ..OD ........QL
0070 2e 52 45 50 2e 36 30 39 33 34 32 32 31 2e 30 34 .REP.60934221.04
0080 39 30 32 39 37 39 2e 30 31 00 00 00 00 00 00 00 902979.01..... . .
0090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 51 4d ..............QM
00a0 2e 30 34 39 30 32 39 37 39 2e 30 31 00 00 00 00 .04902979.01....
00b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 .............. .
00d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4d 55 ..............MU
0100 53 52 5f 4d 51 41 44 4d 49 4e 01 10 00 00 SR_MQADMIN....
Thanks,
Fabricio Oliveira
(91)-8112-1932
- Prev by Date: [Wireshark-users] Help with GRE encapsulated packets
- Next by Date: Re: [Wireshark-users] Help with GRE encapsulated packets
- Previous by thread: Re: [Wireshark-users] Help with GRE encapsulated packets
- Next by thread: [Wireshark-users] RHEL Package Installed, but where's the executable?
- Index(es):