Sorry if this is a bit off topic for the group.
I have an issue that I am troubleshooting where a vendor indicates their box is losing connectivity between the client and server which is causing application issues.
I SPAN'ed the port (Cisco 2960) of the client and am going through the captures and I noticed something that struck me as odd.
Client issues a FIN, ACK Server issues a FIN, ACK
However, after those FIN's I never see any ACK's from either side.
At this point the client starts attempting to reestablish the connection (multiple SYN attempts) with no response from the server.
After approx 10 attempts (20 seconds) the client issues a RST with an ACK. This packets SEQ=0, ACK=1
If there is no associated connection so how can it issue the RST with an ACK?
After it issues this RST packet it immediately establishes the connection.
Questions:
1.) Is it normal to see a RST packet not associated with an active connection have the ACK flag set? 2.) Speculation: because each side never really acknowledged the connection close I suspect the connection may still be open on the server end and the RST packet closed it on the server allowing it to be recreated?Any thoughts regarding this? Sorry about the OT nature of this.
Amy.