Noah Davids - Interesting Traces
The following are traces that I have collected that demonstrate something interesting. They have been collected from a number of operating systems and with different tools so the formats will vary.
Firewall Resets
Reset triggered by keepalive packet after 2 hour delay
Reset triggered by delay caused by retransmissions
Windows 2000 Ignores an connection attempt
FTP aware NAT device causes FTP process to loop for 2 days sending control messages
WINS Active name error but no one else is using the name
Tracing showing what it looks like when a server is hung and its connection backlog queue becomes full
VOS 14.6.0 - TCP_OS
- Listening on port but does not respond to SYNs
VOS 14.6.0 - STCP
- Listening on port but responds to SYNs with resets
Microsoft Windows 2000
- Listening on port but responds to SYNs with resets
Linux 2.4 - Read Hat 7.2
- Only the SYN is ACKed
ARP reply is for the broadcast address
Strange frames from a CheckPoint firewall cluster
Trace shows nothing but DNS queries
Faulty Dead Gateway Detection on HP UX 11x
DHCP and DNS problems when a client set his personal firewall to filter more than it should
A loop in the routing tables
The IP address of one interface appears on the network segment of another interface when sending a limited broadcast packet on Windows 2000 server system
An FTP daemon never sends a banner message so the client never prompts for a password and eventually disconnects
NAT device fails to translate embedded IP address in FTP port command. The result is that the client can connect to the FTP server but can't do anything once they are connected.
Every other packet transmitted from a host is being dropped
Odd length packets do not get a response (destination sees CRC errors)
Bogus packets in traces taken on SPAN ports
Bogus Duplicate Packets
Duplicate Broadcasts
Sometimes the network isn't the problem
ICMP Destination unreachable, fragmentation needed sent by host with wrong IP address
ARP cache thrashing
Ignoring Destination unreachable, fragmentation needed messages
Bogus checksum errors
Unicast ARP Requests
Wrong router response from traceroute
Host based analyzer does not show what is really sent on the wire
Protocol Analyzer's expert analysis may not be so expert
Wireshark incorrectly reports a bad FCS on an ARP frame
Ping reports a timeout but trace shows the reply was sent
Connection request receives ACK before SYN-ACK
Multiple MAC addresses for the same IP address
Multiple MAC adresses for the same IP address
Multiple responses to an ARP request
Server responds to connection request with old sequence numbers
Something is rewriting sequence and acknowledgment numbers
FTP server's IP address is changing in the middle of an FTP session
The perils of port reuse
Checksum errors
TCP backlog capture
Checksum errors - again
Out of Order versus Retransmissions
This page was last modified on 14-05-05
Send comments and suggestions
to noah@noahdavids.org