Hi, We run an RDP session from LAN PCs to a remote hosted desktop over the internet. All has been fine until one thing changed. The UTM. We have gone from a Netgear UTM 25 to a Cyberoam cr25iNG. Since this has happened an RDP session will 'drop' and then reconnect automatically. I am new to wireshark and I have a screen shot here which I'd like to use as an example of something odd to an expert eye. They look like keep alives from the remote host, that are actually ACKd. But a second later the same keep alive is sent and again ACKd in a burst. I need to get more data to see if these conincide with drop out but could it be an indication? Many thanks, Andy. asked 09 Feb '17, 11:53 Flattened |
I have also spotted at a definite cut off time (& at another 2 TCP streams so far what appears to be the PC initiating a 'RST' (see 5309). Any ideas why this would be?
Could you share us a trace? https://blog.packet-foo.com/2016/11/the-wireshark-qa-trace-file-sharing-tutorial/
Hello thankyou for the response.
https://www.cloudshark.org/captures/5e787a7aa5fb
There are RST at frames 2358, 2410 and 4023 in this one.
I can´t tell you the reason, but at some point the server doesn´t answer anymore. Afterthat 20 sec later, the client sends a RST and opens another session.
That's a pity I hoped it could be spotted. Thanks for looking Christian. Andy