Forum Discussion
Ken_B_50116
Cirrostratus
Mar 25, 2015Servers using LTM as its gateway can ping but can't connect on 443
I have a situation where a group of servers that use LTM as their gateway can successfully ping and tracert to servers in a totally different subnet, but are unable to connect on port 443.
Speci...
- Mar 25, 2015
I keep thinking asymmetric routing... but your ports match up. a tcpdump on the F5 may give you more info where you could see all the MAC addresses.
gsharri
Altostratus
Mar 25, 2015I think your tcpdump is showing some problems. I see two syn packets with the same seq number initiated from the 10 host: 10.54.13.101.14196 > 172.22.0.100.https : S the first one with a correct cksum the second is incorrect and the TTL has been decremented compared to the first.
Then I see the 172 host respond with a syn-ack 172.22.0.100.https > 10.54.13.101.14196: S,...ack. But then the 172 host initiates another connection to the 10 host 172.22.0.100.46740 > 10.54.13.101.14196: S and the cksum is incorect.
Then the 10. host sends tcp resets to 172.22.0.100.https and 172.22.0.100.46740. Again one cksum is correct the other incorrect.
There is something strange happening here, not sure what it is...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects