Wireshark-users: [Wireshark-users] Terminal Server traffic

From: "Albert Jurado" <ajurado@xxxxxxxxxxxxxxxx>
Date: Mon, 10 Mar 2008 12:23:38 -0400

As of last week we started to monitor traffic from our internal Terminal Server to our internal SQL server using wireshark.

 

Our network is segmented in the following way:

VLAN for servers

Data VLAN for each floor in the building (six in total).

We installed wireshark on a separate workstation plugged into our core router with a monitoring port configured

 

Our first capture revealed over 40% of the traffic as “out-of-order” packets.  When we performed a capture from the terminal server there was no such traffic. 

I wondering if this type of behavior is normal for terminal server communication.  I hope someone can shed some light on this matter for me, it would greatly appreciated.

 


Thanks!

 

Albert Jurado

Network Manager

First Commercial Insurance Company

2300 W 84 St.

Hialeah, FL 33016

Phone: (305) 820-4848 ex. 1206

Mobile: (305) 873-4400

Email:  ajurado@xxxxxxxxxxxxxxxx