Tuesday, November 21, 2017

No TCP handshake?

So I have tried to find another topic about this with no luck. I have a log server that is being accessed over port 1433. On computers this is working with, a sniff on my firewall shows what I would expect. PC->Server / Server->PC:1433 SYN- SYN ACK - ACK- PSH - with SYN flags inbetween the rest of the ACK flags.

The PCs that aren't working, the traffic I'm sniffing on the firewall only shows. PC->Server:1433 ACK Server->PC:1433 ACK PC->Server:1433 ACK Server->PC:1433 ACK Etc....

The log application allows the user to login, but then just sits there loading. I let it sit for 10 minutes of consistent traffic without a single SYN, PSH, RST, FIN.

I see the traffic passing on both sides, so I know it's getting through but I can't figure out what the flags on the non-working PC are telling me. The networks are coming in on VPNs, and this is with multiple systems also, so I know it isn't the PC itself.

Anyone have any tips?



No comments:

Post a Comment