Forum Discussion
Issue with Capturing SYN-ACK Packets on F5 BigIP Virtual Server
Hello,
The traffic in the packet captures could be hidden if it is offloaded. This use to happen in fastL4 virtual servers and you can disable it by changing to Standard modifying the fasL4 profile.
Anyway, in this case I would bet that the SYN-ACK is goign through other device and the F5 is not seeing it. The F5 is forwarding the SYN packet and blocking the other traffic coming from the client because the session is not established yet. The reset you have at the end is created by the f5 because the session could not be established.
I think the best way to know where this SYN-ACK is going through is to capture the traffic in the client and check the source mac. This way you can probably check who is sending it.
Regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com