Tough problem! TCP reset issue

From: Andy Low (spider_at_bgp5.net_REMOVE_)
Date: 02/27/04


Date: Fri, 27 Feb 2004 17:21:48 +0800

Hi,

Encounter some problem with my Server. To understand this require good
knowledge in TCP/IP Segment and 3-way handshakes

Here is the sequence of 3-way handshakes:

1) Host B --> Host A, src port:1878 dst port: 2000
[SYN] Seq=0 Ack=0 Win=16384 Len=0 MSS=1460

2) Host A --> Host B, src port: 2000, dst port: 1878
[SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=536

3) Host B --> Host A,
[TCP ZeroWindow] src port:1878 dst port:2000 [RST]
Seq=1 Ack=1576600895 Win=0 Len=0

More information:

1) Host B has not problem connecting to Host A all the while.

2) When Host C starts to download file from Host A, Host B gets connection
error

3) In packets debugging, it shows Host B send RST packets to Host A to
terminate the connection.

4) The TCP 3-way handshakes are not able to establish at all. SYN-ACK can
not be acknowledged by Host B.

Hope anyone can help,

Andy



Relevant Pages

  • Re: Number Matching
    ... >On iqtest.com there is an IQ test that includes the clause "a total of 42 ... Is that correct, or should it be, "a total of 42 handshakes ... infectious plague envelops its host" ... Prev by Date: ...
    (alt.usage.english)
  • understanding chkrootkit: sshd section
    ... Rhosts Authentication disabled, originating port will not be trusted. ... Secure connection to %.100s on port %hu refused%.100s. ... Warning: Remote host refused compression. ... Received RSA challenge from server. ...
    (comp.os.linux.security)
  • understanding chkrootkit: sshd section
    ... Rhosts Authentication disabled, originating port will not be trusted. ... Secure connection to %.100s on port %hu refused%.100s. ... Warning: Remote host refused compression. ... Received RSA challenge from server. ...
    (comp.security.unix)
  • Re: ICS and FS trouble
    ... >>>client for ms networks, service advertising protocol, file and printer ... >>>execept that the MS beta AntiSpyware connects to the internet and recognises ... >> Microsoft doesn't support changing the ICS host computer's LAN ... >> Internet connection has a 192.168.0.x address that can't be changed to ...
    (microsoft.public.windowsxp.network_web)
  • Re: understanding chkrootkit: sshd section
    ... Connection will not be encrypted. ... > Rhosts Authentication disabled, originating port will not be trusted. ... > Could not request local forwarding. ... Remote host failed or refused to allocate a pseudo tty. ...
    (comp.os.linux.security)