Solved

TCP/IP: 3-way Handshake

Posted on 2007-04-08
5
3,384 Views
Last Modified: 2012-06-21
Hello Experts,

I have a question regarding the 3-way tcp handshake.  Where does the fault lies when the sender does not send back an ACK?  This is the situation that I am currently getting.  We have two sender, A and B.  

A --> B     [SYN]
B --> A     [SYN, ACK]
A --> B     No response

Does this mean that A did not get the [SYN, ACK] from the second phase of the handshake?  Or did "A" block the third phase?  Can someone clarify this for me.  As always, thank you for your time on this matter...it is always appreciated.
0
Comment
Question by:coperator
  • 2
  • 2
5 Comments
 
LVL 8

Accepted Solution

by:
RGRodgers earned 250 total points
ID: 18873513
A should either ACK (called a SYN ACK ACK) or a NACK for either a bad message or timeout if A gets nothing from B.  A appears at fault.
0
 
LVL 5

Expert Comment

by:skaap2k
ID: 18885714
There could be a issue where one of these devices is using TCP SYN Cookies and the other does not know how to handle it (unlikely)

The best way to find out what is going on, is to take a Ethereal/Wireshark trace from both devices, and see whether A is indeed receiving the SYN ACK, and if it is sending the ACK/SYNACKACK to B ..

RN
0
 
LVL 8

Expert Comment

by:RGRodgers
ID: 18885845
All true, especially the Wireshark comment.  

However, whether A knew how to handle it or not, or received the ACK or not, A was obligated to respond with a SYN/ACK/ACK or a NACK.  No response is never correct.

But, do the trace and tell us what you see!  Thanks...
0
 
LVL 1

Author Comment

by:coperator
ID: 18888560
Unfortunately, I have no control of the other device.  It belongs to a client.  One thing I'd like to mention is the physical layout and where I was able to do a tcpdump.  Will call the client router A and my PIX B (OUTSIDE interface) and both are interconnected thru a switch C.

A -> C -> B

I was able to do a tcpdump from C.  I discovered that there was a Linux box setup to sniff and the port was configured for spanning.  So, that's were I was able to capture the packets.  Now, base on what I had described above, it seems that it is leaving my OUTSIDE interface of my PIX but I am not able to get an ACK from A.  Base on the conversation above, does this confirm that A is at fault?

As always, thank you for your time on this matter.
0
 
LVL 5

Assisted Solution

by:skaap2k
skaap2k earned 250 total points
ID: 18888587
More than likely, yes, that would be the issue.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Please see preceding article here: http://www.experts-exchange.com/Networking/Operating_Systems/A_11209-Root-Bridge-Election.html Figure 1 After Root Bridge has been elected, then what?..... Let's start by defining a Root Port in la…
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now