Hi there, While troubleshooting a SSLVPN slowness issue, I noticed the Retransmitted SSL packets contains multiple app_data sections. I don't see this kind of pattern in pcap files from other locations. The VPN Server has Nagle's algorithm turned on, could this be the cause? The following is an excerpt from the actual capture and in the SAME TCP stream. (For security reasons, the server's public IP is replaced with A.A.A.A). The server was trying to resend TCP Seq 32132 in packet 274, 277 and 281. Notice in each of those packet, there are 3 or 4 "Application Data section"? And also each packet's Next Sequence number is different. Why is that?
Hope someone could kindly clarify. Thanks! ~ asked 17 Nov ‘14, 20:17 Timbit |