Forum Discussion
Tcpdump/wireshark question
Good morning everyone,
We've got a capture traffic taken from an F5 (not sure which model, 11.2.x software release) to catch traffic coming/going to a virtual server configured with a FastL4 profile. When this capture is opened with Wireshark we randomly see bursts of "suspected" retransmissions on both client and server side of the F5. However the same capture taken in our server does not show any sequence being retransmitted.
See attached screenshot (source IP removed for confidentiality reasons):
Is this effect due to tcpdump limitations or to the way Wireshark decodes the capture?
Thanks in advance, moog67
3 Replies
- What_Lies_Bene1
Cirrostratus
Are you capturing on multiple interfaces? If the data is captured from both sides of the proxy its probably confusing Wireshark as its seeing every packet twice.
- What_Lies_Bene1
Cirrostratus
That'll be multiple interfaces then, just ignore the Wireshark error.
To capture on ALL interfaces use
-i 0.0For independent, per VLAN:
-i vlanXXXYou might also want to capture the full packets using
-s0 - JRahm
Admin
New article on wireshark configuration for windows: https://devcentral.f5.com/articles/getting-started-with-the-f5-wireshark-plugin-on-windows
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com