Forum Discussion
How to analyze Loadbalancer packet trace through Wireshark
Dear Exeperts,
I am between one issue where i need to analyze the packet trace captured from Loadbalancer & i need to analyze the same through Wireshark.
Kindly suggest me the resources/guides on how to analyze packet traces in wireshark.
3 Replies
- janholtz
Altostratus
F5> tcpdump -s0 -nnvvi 0.0 host -w /tmp/trace.pcap WinSCP > copy trace.pcap local *nix > scp user@f5:/tmp/trace.pcap /tmp/
Wireshark: Open file: trace.pcap.
Helping?
- janholtz
Altostratus
Duplicate ACKS/RESETS indicates a L2 issue, switching and / or routing. Do you have LACP enabled? Also, you can try to create a fastL4 vs (if you dont need ssl termination / content based routing etc). Create a FastL4 profile with Loose initiation / loose close / NO reset on timeout. Apply this profile to the vs used above.
You now have a VERY stupid L4 load balancer / router, that does virtually nothing to the traffic (doesn't even terminate TCP).
See if that performs better...
- JG
Cumulonimbus
You might want to have a look at the following:
https://devcentral.f5.com/wiki/AdvDesignConfig.F5WiresharkPlugin.ashx
https://devcentral.f5.com/articles/getting-started-with-the-f5-wireshark-plugin-on-windows
.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com