Hi, Kindly help based on 2 capture below, why the delay / error ?
client = 192.168.19.175 ( NAT IP : 192.168.30.134 ) Server = 192.168.5.18 virtual IP ( node C IP : 192.168.5.113 )
Server under the NLB....
Below capture from client to Node C
Below capture at Server Node C
asked 11 Jan '16, 03:22
It seems that your NAT box establishes the tcp session locally before receiving the SYN,ACK from the real server, so when the client starts sending real data packets, the NAT box is unable to forward them because the session at public side has not been established yet.
As for the reason why the server ignores the incoming SYN packet: seeing the "tcp port numbers reused" expert info at the first occurrence of the SYN packet together with the time it took the server to respond the SYN packet, I would assume that the previous session to the server from the same source socket (of the NAT) has been closed from client initiative, and thus the server has been in TIME_WAIT state since then and has responded the SYN only after that state has timed out. Look at the last packets with same source and destination port which came before the first SYN to confirm this.
answered 11 Jan '16, 04:01
edited 11 Jan '16, 04:03