Wireshark-users: Re: [Wireshark-users] TCP checksum off-by-one errors?

Date: Wed, 4 Mar 2009 16:16:58 +0000 (GMT)
Hi Matthias

>Both observations you described seem to deal with the firewall sending
>wrong checksums. In my case the received packets are wrong.

Well - the way you decribed the problem lead me to believe that there is a firewall in the path between sender and 
receiver. And if this firewall does NAT and/or Initial Sequence Number randomization, it will also have to rewrite the 
checksum so that the checksum is valid for the rewritten packet. That process might be faulty, hence the firewall would 
actually be the source and cause of the invalid checksum values.

Are you able to sniff out these packets on both sides of the firewall and compare them to each other in W'shark?

regards

Marc