Forum Discussion

Prince's avatar
Prince
Icon for Altostratus rankAltostratus
May 12, 2017

How to differentiate SYN packet from monitoring traffic and actual application traffic ?

Hi All,

 

I am trying to investigate a monitor flap issue.

 

Monitor used is tcp_half_open

 

SNAT automap is being used on VS.

 

Packet capture during issue is around 200 MB.

 

Checking the capture file i see lot of SYN packets, is there any way i can identify the specific monitoring traffic ?

 

1 Reply

  • Wouldn't the monitor traffic be coming from the self ip addresses, whereas client traffic would be coming from the SNAT ip address(es)?