This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello, I am troubleshooting a baffling situation where a windows workstation with IP 10.167.178.6 is unable to RDP into windows server at IP 10.0.129.208. There are no connectivity issue between the client and the server other than RDP. There is no ACLs on the routers between the two, and no firewall.

The RDP session does connect initially and the user is prompted for for login credentials, but upon authentication the RDP just hangs. Packet capture shows TCP re-transmissions... I need help decrypting what is causing those retransmissions and the RST. I would greatly appreciate any feedback. Thank you in advance.

See link below for the pcap:

https://www.cloudshark.org/captures/6ccd1d7f4690

asked 06 Sep '16, 22:54

pc7's gravatar image

pc7
6113
accept rate: 0%

edited 06 Sep '16, 22:55

Just a blind shot - I had a similar situation a couple of months ago. The remedy was to disable jumbo frames in the network card settings of the server. I haven't captured the traffic back then, though.

(07 Sep '16, 06:20) sindy

Hi Sindy, thank you for the feedback. I'll look Jumbo frames.

(07 Sep '16, 11:44) pc7

Seems that that the client did not receive all packets from the server (packet loss).For example: The ACK for Frame 4 is missing.

If I where you, I would trace as close as possible next to the server, but not onside.

Is the server on a virtual machine? Have checked the network path (CRC Counters)?

(07 Sep '16, 13:53) Christian_R

Hi Christian_R, yes the server is a virtual machine. I will check the network for CRC counter error. Thanks

(07 Sep '16, 14:00) pc7

Ok, good that you Check the network for CRC. But it could be that you got the packet loss inside the vm.

(07 Sep '16, 15:46) Christian_R
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×81
×22
×16

question asked: 06 Sep '16, 22:54

question was seen: 1,436 times

last updated: 07 Sep '16, 15:46

p​o​w​e​r​e​d by O​S​Q​A