Solved

FTP Problem through a switch

Posted on 2012-04-09
13
457 Views
Last Modified: 2012-04-11
Experts,
 I need an expert to read a wireshark and let me know what you think may be causing my FTP data not to transfer after 50%


Thanks,

TamscoDan
FTP-ERROR.csv
0
Comment
Question by:TAMSCODAN
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 5
13 Comments
 
LVL 28

Expert Comment

by:Bill Bach
ID: 37827762
Can you post the original PCAP file?  Analyzing a network via Excel is kind of like driving a cow to work.  It might be possible, but it's REALL slow going...
0
 
LVL 28

Expert Comment

by:Bill Bach
ID: 37827874
The first part of the failure shows that the ACK's simply start to stall out.  Either the receiver is too slow to process the data, or something is blocking the ACK packets:

Screen1
I indicated for each ACK which packet it is ACKing with the arrow.  The retransmissions at the end show that it is having lots of problems, and it is already stalling out.  A little while later, the same thing happens (but it is not as clear without being able to drill down into the TCP layer) and the transfer simply stops.

My guess?  Something is hampering the flow of data (the 64-byte ACK packets) from the target back to the source.  Could be as simple as a bad cable, traffic shaping on a link, or even a misconfiguration of duplex settings.
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 37830264
I'd also check that there's not an MTU issue.

From a command prompt (assuming you're using Windows) try this...

ping <ftpserverip> -f -l 1460

Open in new window


If you get this...

Packet needs to be fragmented but DF set.

...there is a problem with MTU.
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37830945
I have atatched the PCAP you will need to add the extension since it would not let me load it. It is zipped.
FTP-ERROR.zip
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37830963
One interesting test that we did do is that we put in a media converter and connected it into one of the copper ports of the switch and the transfer worked just fine. Than I looked at the specifications of the Media converter and found that the Media converter is rated at a distance of 2km where as the SFP that it was originally connected too was rated to 4Km. Do you think that the laser may be overpowering the rx port on the other end? wavelength is the same.
0
 
LVL 28

Accepted Solution

by:
Bill Bach earned 500 total points
ID: 37832636
That makes it easier to see the exact combination of ACKs:

ScreenShot
Here, we see the TCP window is still around 2900 bytes (two packets), which seems very small (must be an older OS on the target side).  Again, I've highlighted the ACKs for the data packets so you can see what is being ACKed.  Notice, though, the Delta Time column -- there is already an incredible time delay in these packets, with some replies coming many seconds after the requests, causing retransmissions.  

If you look deeply, however, it looks like things SHOULD be still under-way: the ACK is for 541961 (meaning that the target wants this packet next), and we see the exponential fallback as expected (right at the end in the retransmissions) as the source tries to re-send packet 541961 over and over again, but the target just keeps ACKing the same 541961 over and over again, very slowly.  This tells us that it is not receiving the data for some reason.

My guess is that the TCP stack on the target is a bit outdated.  You don't describe the network setup in detail, so coming to a conclusion is all but impossible.  For example, I *never* would have suggested to change out a media converter because you never mentioned that there was one in the loop!
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37832667
Topology is:

(END DEVICE A) ----via copper-----(Switch with Copper and Fiber)--------Fiber----------(FTP SERVER)
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37832677
Initially there was no media converter, we used it to test therfore we connected the FTP server that was on the fiber and converted the FIBER to a copper connection so it worked fine that way. So this demostrates there was an issue with the SFP, however I would like to know what was the issue or how to figure this out via the wireshark capture. Great explanantion though!!!!
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37832822
How can i get the Delta colum on wireshark?
0
 
LVL 28

Expert Comment

by:Bill Bach
ID: 37833769
Easy way: Select Edit / Time Display Format / Seconds Since Previous Displayed Packet (This changes the TIME field to the delta time)
Hard Way: Edit the entire column list, add a new column, rename it to Delta Time, and specify the item for Delta Time. (This allows you to have BOTH times shown, like I do.)

You can also show JUST the important traffic by right-clicking on an FTP packet, selecting Filter Conversation / TCP.
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37833806
What prompted you to say incredible time delays? Sorry for all the questions. What should I expect for time delay?
0
 
LVL 28

Expert Comment

by:Bill Bach
ID: 37833845
While the process is running normally (towards the beginning of the process), you'll note the time delay is within a few ms each packet.  By the time it starts failing and the retransmissions start, it is taking over 1/4 second for each ACK (this lack of an ACK is what triggers the retransmission), and subsequent retransmissions are taking SEVERAL seconds.  This is an eternity as far as computers are concerned.
0
 
LVL 3

Author Comment

by:TAMSCODAN
ID: 37833880
Thank you for all this good info!
0

Featured Post

Report: Liquid Web beats Amazon, Rackspace & More

A study by performance analyst firm Cloud Spectator finds that Liquid Web beats rivals Amazon, Rackspace and DigitalOcean when it comes to website and cloud application performance.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question