Forum Discussion

moog67_108621's avatar
moog67_108621
Icon for Nimbostratus rankNimbostratus
Jul 03, 2014

Tcpdump/wireshark question

Good morning everyone,

 

We've got a capture traffic taken from an F5 (not sure which model, 11.2.x software release) to catch traffic coming/going to a virtual server configured with a FastL4 profile. When this capture is opened with Wireshark we randomly see bursts of "suspected" retransmissions on both client and server side of the F5. However the same capture taken in our server does not show any sequence being retransmitted.

 

See attached screenshot (source IP removed for confidentiality reasons):

 

Is this effect due to tcpdump limitations or to the way Wireshark decodes the capture?

 

Thanks in advance, moog67

 

3 Replies