[olug] A TCP/IP mystery

Dave Hull dphull at trustedsignal.com
Thu Mar 13 03:57:09 UTC 2008


On 3/12/08, Dave Thacker <dthacker9 at cox.net> wrote:
> If I was to start monitoring with those tools. what would a "block" look like?

Not sure about iptraf, but assuming it works similar to tcpdump, you
may see a high number of retransmists due to lost packets. I'd start
with a sniffer on both ends. I like Wireshark and it's cli equivalent
tshark.

If memory serves (does it ever?), I remember diagnosing a connection
problem that involved window scaling. Are these two boxes on the same
subnet? Apparently some networking gear (layer 3) may mangle the
window scale value and this can make things suboptimal.

--
Dave Hull



More information about the OLUG mailing list