Retransmissions over fortigate ipsec vpn

  • retag add tags

I am troubleshooting a print delay/pausing issue over a vpn. Printers are on one side of the tunnel, the application is on the other. printers randomly stop and start printing. Only thing i am seeing on the packet caps is dups/retransmissions but cannot figure out why

here is a link to the pcap - link text

fredsavage's avatar
1
fredsavage
asked 2020-07-08 14:28:36 +0000
edit flag offensive 0 remove flag close merge delete

Comments

Have you looked at the details on those packets?

Try setting the display filter to tcp.stream == 1 and the Time Display Format to Seconds since previous displayed packet.

Now look at these packets again and see that every packet is repeated with a very short delay. Let's call these 'pairs'. Now look at the IP layer of these packet pairs, in particular the Time To Live. You'll notice that in each pair these differ by 1. So either two packets appear at the interface via their own route, or the capture setup is such that the ingress and egress packets are captured.

And what's happening with these MAC addresses being 00:00:00:00:00:00?

Jaap's avatar Jaap (2020-07-08 16:54:20 +0000) edit

The capture was taken from the fortigates sniffer from one side of the tunnel. There is only one route

fredsavage's avatar fredsavage (2020-07-08 19:12:31 +0000) edit

Can you make a capture to a working printer to compare?
Can you make a capture near the printer to see if it receiving and responding to the LPR packet from the client?
This Red Hat Bugzilla has nothing to do with the issue but does have a pcap attached to it showing a full LPD TCP conversation.

Chuckc's avatar Chuckc (2020-07-08 19:37:50 +0000) edit

So, looking at this it would be interesting to know what drag sniffer packet command you actually used. And assuming you used fgt2eth.pl you got a pcap file with everything in it. If you were sniffing on 'any' interface that would explain a lot.

Jaap's avatar Jaap (2020-07-09 16:22:57 +0000) edit

I retook the capture from a span port on the same switch. capfile below - notice the big pause @ timestamp12:02:27 https://www.mediafire.com/file/fc22ls...

fredsavage's avatar fredsavage (2020-07-14 16:14:17 +0000) edit
add a comment see more comments