当前位置:网站首页>Wireshark packet capturing: error analysis
Wireshark packet capturing: error analysis
2022-07-19 06:49:00 【Did you learn to waste today】
- It's been too long , Briefly remember a part , Get off work first
Tools :wireshark
Commonly used wireshark Filtering rules :
1、 Address filtering
ip.src Source
ip.dst Purpose
ip.host After parsing the data
ip.addr Some address
( Filter IPv6 Use ipv6.*)
ip.addr > && ip.addr < Display address range
2、 Port filtering
agreement .port== port , Filter out relevant protocol packets
* DHCP Filter
DHCPv4 Use bootp Syntax filtering ,IPv6 Not based on bootp Of , Use DHCPv6
3、 Filter single TCP/UDP conversation :
Packet List Right click , choice Conversation Filter|TCP/UDP
4、 Tracking flow
Right click for a moment :Fallow Stream
One 、 Response problem :
1、 Mass retransmission :
It takes a long time for the other party to respond , Normally, there is no retransmission : It may be because the network is unstable , Capture packets in the intermediate device and check the location of packet loss 
Mass retransmission and dup ack, There should be packet loss in the link , Image traffic is convenient for troubleshooting
2、 Slow response : Check each other 

TCP Keep-Alive: Keep alive detection mechanism . Avoid when both sides of the connection are idle , Either party fails , The other party will maintain the link without knowing , The resulting resource consumption and the possibility of sending business data at an invalid data link level , Send the result of failure .
Load device forwarding problem :
1、 Memory 、 disk 、CPU usage
2、 Check whether there is an alarm in the log
3、 Configuration problem
F5 in Take the initiative to drop:
1. Received packets VLAN ID And interface VLAN Mismatch
2. Unknown data type
3. Connect the device port flooding packet
Slow server response :
1、 Client pass ping、curl This method eliminates the problem of whether it is the client or the server
2、 Check the server load 、 The disk is 、 Memory 、 journal 、 Whether the application is abnormal
3、 Number of database connections 、 Active threads 、 The query efficiency
4、 File server 、 Cache server load 、 The disk is 、 Memory 、 journal 、 Whether the application is abnormal
Two 、 Connection setup failed :
( Take packet capturing on load balancing devices as an example )
1、 The server is not responding :(Performance L4 type VS,6-9 Package No. client >F5> The server , No problem )
F5 After the address is transferred, it is sent to the server , The server is not responding ,F5 send out RST disconnect 
The client passes by F5 And then sent it to the back-end server syn My bag , The server did not respond 
F5 After sending three retransmissions, there is still no return from the server , Take the initiative to send RST disconnect , There is no problem with device forwarding , Page error is 504 Prompt that the server did not respond , Whether there is a wall to intercept 

2、 Intermediate equipment MAC The address is wrong : View device mac Whether it is right , This situation is whether there is a problem with the subcontracting of intermediate equipment , It is suggested to check from the intermediate equipment mac.


3、 Routing points to problems :
Returned the wrong VLAN(id by 16), This... Is not available on the load device VLAN(F5 Send back VLAN id by 12)
3、 ... and 、DOS problem :
It was sent by a single user from the same source port DNS package , The peak is per second 125krps, In this way, the traffic users go to the same cpu The device performance cannot be supported .
WireShark Refer to the previous article for message related information :
https://blog.csdn.net/qq_43148894/article/details/120038136?spm=1001.2014.3001.5502
边栏推荐
- 2022-7-15 cheap domestic PLC industrial control board with scattered records of 485 master-slave communication
- 《PyTorch深度学习实践》-B站 刘二大人-day5
- 小迪网络安全-笔记 加密编码算法(6)
- C 语言结构体数组指针以及函数
- 明明爱喝水
- 渣渣学习之路(2)纯小白向:Win Server 2003服务器搭建
- IDEA中@Resource爆红
- 吴恩达机器学习第14-15章
- Experiment 4 operator overloading and virtual functions
- F5ltm (I) logic diagram
猜你喜欢

Talk about Zhongtai: my understanding and thinking about Zhongtai

2019cs brand sdnand and EMMC selection comparison important analysis

锁

管理员阻止运行此应用
小迪网络安全笔记-信息收集-架构、搭建、waf(8)

No application for domain name SSL certificate under ports 80 and 443 (applicable to acme.sh and certbot)

《PyTorch深度学习实践》-B站 刘二大人-day3

Wu Enda machine learning chapter 3-4

渣渣学习之路(2)纯小白向:Win Server 2003服务器搭建

️️固高运动控制卡的相关知识点
随机推荐
汉诺塔2(函数)
Machine learning - classification prediction of logistic regression
MySQL MySQL calculates the number of weekends this year (Saturday and Sunday)
From entering URL to displaying page
小迪网络安全-笔记(4)
释放nohup.out占用的磁盘空间
2019cs brand sdnand and EMMC selection comparison important analysis
Relevant knowledge points of Gugao motion control card
Restapi implementation of automatic completion & case implementation (search box input for automatic completion)
Thales安全解决方案:怎么提高国家网络安全的关键步骤
Part of the second Shanxi Network Security Skills Competition (Enterprise Group) WP (III)
F5 GTM (I): DNS parameters
翻转链表
Experiment 3 inheritance and derived classes
高并发day04(ZAB协议,观察者,nc,AVRO,RPC)
wireshark抓包:错误分析
小迪网络安全笔记 信息收集-CDN绕过技术(7)
notepad++下划线以及大小写字母置换
Openssl--- stack
TCP/IP协议学习