I am seeing a lot of retransmissions sending data from one
computer in a client corporate network via SSL to one of my servers across the
Internet. I am not sure I understand how to decipher the reason for the
retransmissions. I have a lot of other computers at other clients interacting
with the same server with no problems using the same protocol. The following is a example of a wireshark trace of the
interaction… checksum errors are a result of TCP offload. Same problem
without the flag when I switch that off. Thanks for any help. No.
Time
Source
Destination
Protocol Info 3077 39.847482
10.0.0.61
192.168.0.182
TCP 37946 > https [SYN] Seq=0 Win=65535 Len=0
MSS=1460 Frame 3077 (62 bytes on wire, 62 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 0, Len: 0 No.
Time
Source
Destination
Protocol Info 3078 39.884360
192.168.0.182
10.0.0.61
TCP https > 37946 [SYN, ACK] Seq=0 Ack=1
Win=16384 Len=0 MSS=1380 Frame 3078 (62 bytes on wire, 62 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 0, Ack: 1, Len: 0 No.
Time
Source
Destination
Protocol Info 3079 39.884375
10.0.0.61 192.168.0.182
TCP 37946 > https [ACK] Seq=1 Ack=1 Win=65535
[TCP CHECKSUM INCORRECT] Len=0 Frame 3079 (54 bytes on wire, 54 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 1, Ack: 1, Len: 0 No.
Time
Source
Destination
Protocol Info 3080 39.884576
10.0.0.61
192.168.0.182
SSLv3 Client Hello Frame 3080 (156 bytes on wire, 156 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 1, Ack: 1, Len: 102 Secure Socket Layer No.
Time
Source
Destination
Protocol Info 3081 39.921355
192.168.0.182
10.0.0.61
TCP [TCP segment of a reassembled PDU] Frame 3081 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 1, Ack: 103, Len: 1380 Secure Socket Layer No.
Time
Source
Destination
Protocol Info 3082 39.922543
192.168.0.182
10.0.0.61
SSLv3 Server Hello, Certificate, Server Hello Done Frame 3082 (836 bytes on wire, 836 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 1381, Ack: 103, Len: 782 [Reassembled TCP Segments (2162 bytes): #3081(1380),
#3082(782)] Secure Socket Layer No.
Time
Source
Destination
Protocol Info 3083 39.922558
10.0.0.61
192.168.0.182
TCP 37946 > https [ACK] Seq=103 Ack=2163 Win=65535
[TCP CHECKSUM INCORRECT] Len=0 Frame 3083 (54 bytes on wire, 54 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 103, Ack: 2163, Len: 0 No.
Time Source Destination
Protocol Info 3084 39.923485
10.0.0.61
192.168.0.182
SSLv3 Client Key Exchange, Change Cipher Spec, Encrypted Handshake
Message Frame 3084 (258 bytes on wire, 258 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 103, Ack: 2163, Len: 204 Secure Socket Layer No.
Time
Source
Destination
Protocol Info 3085 39.959760
192.168.0.182
10.0.0.61
SSLv3 Change Cipher Spec, Encrypted Handshake Message Frame 3085 (121 bytes on wire, 121 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2163, Ack: 307, Len: 67 Secure Socket Layer No.
Time
Source
Destination
Protocol Info 3086 39.967659
10.0.0.61
192.168.0.182
SSLv3 Application Data, Application Data, Application Data,
Application Data, [Unreassembled Packet [incorrect TCP checksum]] Frame 3086 (5574 bytes on wire, 5574 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 307, Ack: 2230, Len: 5520 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3087 40.032713
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=3067 Win=64273
Len=0 Frame 3087 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 3067, Len: 0 No.
Time
Source
Destination
Protocol Info 3088 40.032753
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3088 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 5827, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3090 40.067726
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=5827
Win=65535 Len=0 Frame 3090 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 5827, Len: 0 No.
Time
Source
Destination Protocol
Info 3091 40.067740
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3091 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 9967, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3092 40.128280
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=8587 Win=65535
Len=0 Frame 3092 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 8587, Len: 0 No.
Time
Source
Destination
Protocol Info 3093 40.128292
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3093 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst: 192.168.0.182
(192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 14107, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3094 40.186993
10.0.0.61
192.168.0.182
TCP [TCP Dup ACK 3093#1] 37946 > https [ACK]
Seq=18247 Ack=2230 Win=65468 [TCP CHECKSUM INCORRECT] Len=0 Frame 3094 (54 bytes on wire, 54 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 0 No.
Time
Source
Destination
Protocol Info 3095 40.195644
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=11347
Win=65535 Len=0 Frame 3095 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 11347, Len: 0 No.
Time
Source
Destination
Protocol Info 3096 40.195667
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3096 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3097 40.227259
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=14107 Win=65535
Len=0 Frame 3097 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 14107, Len: 0 No.
Time
Source
Destination
Protocol Info 3098 40.227272
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3098 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 22387, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3100 40.320887 192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=16867
Win=65535 Len=0 Frame 3100 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 16867, Len: 0 No.
Time
Source
Destination Protocol
Info 3101 40.320901
10.0.0.61
192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3101 (4194 bytes on wire, 4194 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 26527, Ack: 2230, Len: 4140 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3102 40.337181
192.168.0.182
10.0.0.61
TCP https > 37946 [ACK] Seq=2230 Ack=18247
Win=65535 Len=0 Frame 3102 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Sonicwal_29:14:70 (00:06:b1:29:14:70),
Dst: Dell_23:40:74 (00:14:22:23:40:74) Internet Protocol, Src: 192.168.0.182 (192.168.0.182), Dst:
10.0.0.61 (10.0.0.61) Transmission Control Protocol, Src Port: https (443), Dst
Port: 37946 (37946), Seq: 2230, Ack: 18247, Len: 0 No.
Time
Source
Destination
Protocol Info 3103 40.337191
10.0.0.61 192.168.0.182
SSLv3 Continuation Data, [Unreassembled Packet [incorrect TCP
checksum]] Frame 3103 (2814 bytes on wire, 2814 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 30667, Ack: 2230, Len: 2760 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3120 41.608795
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3120 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 1380 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3150 44.124395 10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3150 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst: Netgear_39:11:fc
(00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 1380 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3201 49.374191
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3201 (590 bytes on wire, 590 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 536 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination Protocol
Info 3232 54.499061
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3232 (590 bytes on wire, 590 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 536 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3311 59.748968
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3311 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 1380 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No. Time
Source
Destination
Protocol Info 3529 70.144576
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3529 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 1380 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] No.
Time
Source
Destination
Protocol Info 3765 90.919969
10.0.0.61
192.168.0.182
SSLv3 [TCP Retransmission] Continuation Data, [Unreassembled
Packet [incorrect TCP checksum]] Frame 3765 (1434 bytes on wire, 1434 bytes captured) Ethernet II, Src: Dell_23:40:74 (00:14:22:23:40:74), Dst:
Netgear_39:11:fc (00:14:6c:39:11:fc) Internet Protocol, Src: 10.0.0.61 (10.0.0.61), Dst:
192.168.0.182 (192.168.0.182) Transmission Control Protocol, Src Port: 37946 (37946), Dst
Port: https (443), Seq: 18247, Ack: 2230, Len: 1380 Secure Socket Layer [Unreassembled Packet [incorrect TCP checksum]: SSL] Ronald S Woan | Director of Development | Azaleos
Corporation | T: 206-926-2000 | F: 206-260-7480 You rely on Exchange. We keep it running. |
- Prev by Date: [Wireshark-users] top talkers by port usage or SYN attempts
- Next by Date: [Wireshark-users] How to switch from "DIgest" Mailing-List mode to "Single Mails" mode ?
- Previous by thread: Re: [Wireshark-users] top talkers by port usage or SYN attempts
- Next by thread: [Wireshark-users] How to switch from "DIgest" Mailing-List mode to "Single Mails" mode ?
- Index(es):