Wireshark-users: [Wireshark-users] "TCP Segment of a reassembled PDU" from a NetApp filer
From: lemons_terry@xxxxxxx
Date: Tue, 18 Mar 2008 21:22:36 -0400
Hi I've read previous posts regarding "TCP Segment of a reassembled PDU", but I still can't figure out why it is happening in my environment. I'm using NDMP between a Windows 2003 system and a NetApp filer. I'm able to have a problem-free NDMP conversation between this same Windows 2003 system and another NDMP-capable system. But the packets sent from the NetApp to the Windows 2003 system all have the "TCP Segment of a reassembled PDU". Not only does this smack of a network problem, but Wireshark can not decode the NDMP of the packets sent from the NetApp. Here are the first few frames of the conversation. Any thoughts? No. Time Source Destination Protocol Info 213 18.582986 192.168.11.115 192.168.11.250 TCP epp > ndmp [SYN] Seq=0 Win=65535 Len=0 MSS=1460 Frame 213 (62 bytes on wire, 62 bytes captured) Ethernet II, Src: tivo1.backup (00:11:43:32:05:93), Dst: Intel_dd:61:b4 (00:03:47:dd:61:b4) Internet Protocol, Src: 192.168.11.115 (192.168.11.115), Dst: 192.168.11.250 (192.168.11.250) Transmission Control Protocol, Src Port: epp (3044), Dst Port: ndmp (10000), Seq: 0, Len: 0 Source port: epp (3044) Destination port: ndmp (10000) Sequence number: 0 (relative sequence number) Header length: 28 bytes Flags: 0x02 (SYN) Window size: 65535 Checksum: 0x3420 [validation disabled] Options: (8 bytes) No. Time Source Destination Protocol Info 214 18.583098 192.168.11.250 192.168.11.115 TCP ndmp > epp [SYN, ACK] Seq=0 Ack=1 Win=8760 Len=0 MSS=1460 Frame 214 (62 bytes on wire, 62 bytes captured) Ethernet II, Src: Intel_dd:61:b4 (00:03:47:dd:61:b4), Dst: tivo1.backup (00:11:43:32:05:93) Internet Protocol, Src: 192.168.11.250 (192.168.11.250), Dst: 192.168.11.115 (192.168.11.115) Transmission Control Protocol, Src Port: ndmp (10000), Dst Port: epp (3044), Seq: 0, Ack: 1, Len: 0 Source port: ndmp (10000) Destination port: epp (3044) Sequence number: 0 (relative sequence number) Acknowledgement number: 1 (relative ack number) Header length: 28 bytes Flags: 0x12 (SYN, ACK) Window size: 8760 Checksum: 0x1c92 [validation disabled] Options: (8 bytes) [SEQ/ACK analysis] [This is an ACK to the segment in frame: 213] [The RTT to ACK the segment was: 0.000112000 seconds] No. Time Source Destination Protocol Info 215 18.583113 192.168.11.115 192.168.11.250 TCP epp > ndmp [ACK] Seq=1 Ack=1 Win=65535 Len=0 Frame 215 (54 bytes on wire, 54 bytes captured) Ethernet II, Src: tivo1.backup (00:11:43:32:05:93), Dst: Intel_dd:61:b4 (00:03:47:dd:61:b4) Internet Protocol, Src: 192.168.11.115 (192.168.11.115), Dst: 192.168.11.250 (192.168.11.250) Transmission Control Protocol, Src Port: epp (3044), Dst Port: ndmp (10000), Seq: 1, Ack: 1, Len: 0 Source port: epp (3044) Destination port: ndmp (10000) Sequence number: 1 (relative sequence number) Acknowledgement number: 1 (relative ack number) Header length: 20 bytes Flags: 0x10 (ACK) Window size: 65535 Checksum: 0x98d8 [validation disabled] [SEQ/ACK analysis] [This is an ACK to the segment in frame: 214] [The RTT to ACK the segment was: 0.000015000 seconds] No. Time Source Destination Protocol Info 216 18.584792 192.168.11.250 192.168.11.115 TCP [TCP segment of a reassembled PDU] Frame 216 (60 bytes on wire, 60 bytes captured) Ethernet II, Src: Intel_dd:61:b4 (00:03:47:dd:61:b4), Dst: tivo1.backup (00:11:43:32:05:93) Internet Protocol, Src: 192.168.11.250 (192.168.11.250), Dst: 192.168.11.115 (192.168.11.115) Transmission Control Protocol, Src Port: ndmp (10000), Dst Port: epp (3044), Seq: 1, Ack: 1, Len: 4 Source port: ndmp (10000) Destination port: epp (3044) Sequence number: 1 (relative sequence number) [Next sequence number: 5 (relative sequence number)] Acknowledgement number: 1 (relative ack number) Header length: 20 bytes Flags: 0x18 (PSH, ACK) Window size: 8760 Checksum: 0xc925 [validation disabled] [SEQ/ACK analysis] [This is an ACK to the segment in frame: 215] [The RTT to ACK the segment was: 0.001679000 seconds] TCP segment data (4 bytes) No. Time Source Destination Protocol Info 219 18.767903 192.168.11.115 192.168.11.250 TCP epp > ndmp [ACK] Seq=1 Ack=5 Win=65531 Len=0 Frame 219 (54 bytes on wire, 54 bytes captured) Ethernet II, Src: tivo1.backup (00:11:43:32:05:93), Dst: Intel_dd:61:b4 (00:03:47:dd:61:b4) Internet Protocol, Src: 192.168.11.115 (192.168.11.115), Dst: 192.168.11.250 (192.168.11.250) Transmission Control Protocol, Src Port: epp (3044), Dst Port: ndmp (10000), Seq: 1, Ack: 5, Len: 0 Source port: epp (3044) Destination port: ndmp (10000) Sequence number: 1 (relative sequence number) Acknowledgement number: 5 (relative ack number) Header length: 20 bytes Flags: 0x10 (ACK) Window size: 65531 Checksum: 0x98d8 [validation disabled] [SEQ/ACK analysis] [This is an ACK to the segment in frame: 216] [The RTT to ACK the segment was: 0.183111000 seconds] No. Time Source Destination Protocol Info 220 18.768162 192.168.11.250 192.168.11.115 TCP [TCP segment of a reassembled PDU] Frame 220 (90 bytes on wire, 90 bytes captured) Ethernet II, Src: Intel_dd:61:b4 (00:03:47:dd:61:b4), Dst: tivo1.backup (00:11:43:32:05:93) Internet Protocol, Src: 192.168.11.250 (192.168.11.250), Dst: 192.168.11.115 (192.168.11.115) Transmission Control Protocol, Src Port: ndmp (10000), Dst Port: epp (3044), Seq: 5, Ack: 1, Len: 36 Source port: ndmp (10000) Destination port: epp (3044) Sequence number: 5 (relative sequence number) [Next sequence number: 41 (relative sequence number)] Acknowledgement number: 1 (relative ack number) Header length: 20 bytes Flags: 0x18 (PSH, ACK) Window size: 8760 Checksum: 0x1d2a [validation disabled] [SEQ/ACK analysis] [This is an ACK to the segment in frame: 219] [The RTT to ACK the segment was: 0.000259000 seconds] [PDU Size: 40] TCP segment data (24 bytes) [Reassembled PDU in frame: 220] TCP segment data (28 bytes) [Reassembled PDU in frame: 224] TCP segment data (12 bytes) [Reassembled TCP Segments (28 bytes): #216(4), #220(24)] Thanks! tl Terry Lemons Backup Platforms Group EMC² where information lives 4400 Computer Drive, MS D239 Westboro MA 01580 Phone: 508 898 7312 Email: Lemons_Terry@xxxxxxx
- Follow-Ups:
- Prev by Date: [Wireshark-users] Important Question about TPKT Protocol and Logical Link Control
- Next by Date: Re: [Wireshark-users] "TCP Segment of a reassembled PDU" from a NetApp filer
- Previous by thread: [Wireshark-users] Important Question about TPKT Protocol and Logical Link Control
- Next by thread: Re: [Wireshark-users] "TCP Segment of a reassembled PDU" from a NetApp filer
- Index(es):