For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Prince's avatar
Prince
Icon for Altostratus rankAltostratus
May 12, 2017

How to differentiate SYN packet from monitoring traffic and actual application traffic ?

Hi All,

 

I am trying to investigate a monitor flap issue.

 

Monitor used is tcp_half_open

 

SNAT automap is being used on VS.

 

Packet capture during issue is around 200 MB.

 

Checking the capture file i see lot of SYN packets, is there any way i can identify the specific monitoring traffic ?

 

1 Reply

  • Wouldn't the monitor traffic be coming from the self ip addresses, whereas client traffic would be coming from the SNAT ip address(es)?