Wireshark-users: Re: [Wireshark-users] Can somebody tell whats going wrong in the connection

From: "Shane Hartman" <shartman@xxxxxxxxxxxxxxxxxxxxx>
Date: Sun, 27 Jan 2008 00:14:53 -0500
It looks like the connection was closed as shown in the first couple lines with the [FIN, ACK]
The other lines after the pings is an attempt by 172.22.1.5 to make a connection to 192.168.94.3 on port 9018. The immediate reset, or [RST, ACK] is symptomatic of a connection attempt to a closed port. I would say check the service on port 9018 and make sure it is running or nothing else is in the way like a firewall.

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of pascalsiekman@xxxxxxx
Sent: Saturday, January 26, 2008 5:39 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] Can somebody tell whats going wrong in the connection

Im having troubles on a connection as shown below.
Can somebody tell me what is going wrong.

No.     Time                       Source                Destination           Protocol Info
    586 2008-01-26 23:01:23.705424 192.168.94.3          172.22.1.5            TCP      9018 > 3890 [FIN, ACK] Seq=190 Ack=861 Win=64216 Len=0
    587 2008-01-26 23:01:23.705527 172.22.1.5            192.168.94.3          TCP      3890 > 9018 [ACK] Seq=861 Ack=191 Win=32483 Len=0
    588 2008-01-26 23:01:23.724122 172.22.1.5            192.168.94.3          TCP      3890 > 9018 [FIN, ACK] Seq=861 Ack=191 Win=32483 Len=0
    589 2008-01-26 23:01:23.724383 192.168.94.3          172.22.1.5            TCP      9018 > 3890 [ACK] Seq=191 Ack=862 Win=64216 Len=0
    590 2008-01-26 23:01:24.554007 192.168.94.3          172.22.1.5            ICMP     Echo (ping) request
    591 2008-01-26 23:01:24.554102 172.22.1.5            192.168.94.3          ICMP     Echo (ping) reply
    592 2008-01-26 23:01:28.722580 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    593 2008-01-26 23:01:28.723213 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=0 Win=0 Len=0
    594 2008-01-26 23:01:29.112215 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    595 2008-01-26 23:01:29.112589 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=1 Win=0 Len=0
    596 2008-01-26 23:01:29.554980 192.168.94.3          172.22.1.5            ICMP     Echo (ping) request
    597 2008-01-26 23:01:29.555070 172.22.1.5            192.168.94.3          ICMP     Echo (ping) reply
    598 2008-01-26 23:01:29.659097 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    599 2008-01-26 23:01:29.659405 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=1 Win=0 Len=0
    600 2008-01-26 23:01:29.706138 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    601 2008-01-26 23:01:29.706488 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=1 Win=0 Len=0
    602 2008-01-26 23:01:30.205933 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    603 2008-01-26 23:01:30.206600 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=1 Win=0 Len=0
    604 2008-01-26 23:01:30.752797 172.22.1.5            192.168.94.3          TCP      4286 > 9018 [SYN] Seq=0 Ack=0 Win=32768 Len=0 MSS=1460
    605 2008-01-26 23:01:30.753150 192.168.94.3          172.22.1.5            TCP      9018 > 4286 [RST, ACK] Seq=0 Ack=1 Win=0 Len=0

_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users