Ethereal-users: [Ethereal-users] Filter for multiple packets

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: CNS - Matthew Bradley <matthew.bradley@xxxxxxxxxxxxx>
Date: Wed, 6 Aug 2003 09:14:46 +0100
All,

We are trying to diagnose problems with an application that uses a
proprietary protocol over TCP. We want to run our test environment for a
number of minutes or hours, and then analyse the captured packets. Our test
environment creates many application level sessions each over a separate TCP
connection. Most of the sessions will succeed, some will fail.

Individual packets on their own do not identify failed sessions. Known
sequences of packets for failed sessions include:

* Initial TCP SYN is responded to with a TCP FIN without any data being
transmitted.
* The TCP connection is correctly established. Then a packet with a known
sequence of bytes at a known offset is sent. No response is ever received.

We want an ethereal filter or some other technique to identify failed
sessions. Does anyone have any suggestions?

Many thanks in advance,

Matthew



CNS
C/O SCT Ltd,
204-207 Western Docks, Southampton, SO15 1DA
Switchboard : +44 (0)845 6589920 Fax : +44 (0)2380 799602
Help Desk : +44 (0)845 6589930
http://www.cnsonline.net/
Reg. no. 2084279 England
*************************************************************
All views or opinions expressed herein are solely 
those of the author and do not necessarily represent those  
of Community Network Services Ltd who do not accept 
liability for any action taken in reliance on the contents 
of this message (other than where the company has a legal 
or regulatory obligation to do so) or for the consequences 
of any computer viruses which may have been transmitted 
by this E-Mail
The E-Mail and any files transmitted  with it, are confidential 
and intended solely for the use of the individual or entity to 
whom they are addressed. If you have received this message 
in error please notify the sender and delete the message 
immediately or alternatively email postmaster@xxxxxxxxxxxxx
***************************************************************