Solved

Wireshark Files Needed to be explained

Posted on 2013-06-12
24
386 Views
Last Modified: 2013-06-26
We have a sonicwall firewall that is in place in our network.  We just had a new phone system put in that will allow vendor to get to it remotely and allow main office to transfer phone calls to branch offices by using VOIP.  There are times where the VOIP feature does not work and the vendor states that the sonicwall is blocking VOIP traffic or packets to their phone system.  We have opened up the ports they need and there are still issues.  They have ran wire shark to show us that that something is blocking the traffic.

If I upload these files can someone read these and tell me what is blocking traffic?  They have wire shark files between the sonicwall and phone system.

Can someone assist me by reading these and letting me know if it is the Sonicwall?
0
Comment
Question by:maximus7569
  • 12
  • 12
24 Comments
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39242281
can you upload it to Google drive and make access available with link?
0
 

Author Comment

by:maximus7569
ID: 39242504
Ok I will do that.
0
 

Author Comment

by:maximus7569
ID: 39242519
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39242769
on which log they saying that sonicwall is dropping pockets?
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39242796
pocket 613- on log beetween sonicwall and vc0 -  "tcp checksum offloading problem"

to fix do that

1. Open Device manager (right click "Computer" and click "Manage")
2. Click on "Device Manager"
3. Expand "Network adapters"
4. Right click your network adapter mine is called "Nvidia nForce 10/100/1000 Mbps Ethernet" etc.
5. click "properties"
6. click the tab named "Advanced"
7. Find "IP Checksum Offload" and click it
8. Put the value to the right to "Disabled"
9. Find "TCP Checksum offload (IPvX)
10. Set the value to the right to "Disabled"
0
 
LVL 14

Accepted Solution

by:
JAN PAKULA earned 500 total points
ID: 39242812
also what sonicwalls you have?

can you tell me what setting you have on these (on both firewalls)

usually under
Firewall > TCP Settings or Firewall > advanced> TCP Settings

Enforce strict TCP compliance with RFC 793 and RFC 1122 - enabled?

Enable TCP handshake enforcement - enabled?

Enable TCP checksum enforcement – If an invalid TCP checksum is calculated, the packet will be dropped. - that might be why you loosing traffic - make sure this one is disabled

Default TCP Connection Timeout – enabled?

Maximum Segment Lifetime (seconds) -enabled?


https://www.fuzeqna.com/sonicwallkb/ext/kbdetail.aspx?kbid=3768&p=
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39242888
if you want you can disable Google sharing - i have all 4 logs
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39244266
any update?
0
 

Author Comment

by:maximus7569
ID: 39244410
Let me look over your responses.  Just saw your responses.  Thanks!
0
 

Author Comment

by:maximus7569
ID: 39244574
The logs that have ICV in them is the ones they state that are blocking packets.
The sonicwall is a TZ100W.
I am looking at the settings you mentioned now.
0
 

Author Comment

by:maximus7569
ID: 39244596
Here are the firewall settings in a snap shot.
0
 

Author Comment

by:maximus7569
ID: 39244600
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39244611
was that original settings ? are you just changed it  to that?

if original try enabling two top ones
0
 

Author Comment

by:maximus7569
ID: 39244645
No I have not made any changes.
0
 

Author Comment

by:maximus7569
ID: 39244648
Ok I will enable.
0
 

Author Comment

by:maximus7569
ID: 39244724
Ok its done.
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39244745
is it working now? have you done changes on both firewalls?
0
 

Author Comment

by:maximus7569
ID: 39244783
Yes I have made changes.  Well its working now, its just later they cant get back into it.  They state that sonicwall starts to block the connection.  I don't understand how the sonicwall will start all of a sudden blocking traffic.   Is that even possible?
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39244801
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39244806
inactivity timouts on udp or sip might be also causing it - second article
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39263058
any update?
0
 

Author Comment

by:maximus7569
ID: 39263205
Seems to be staying stable.  Did you ever see where the sonicwall was blocking packets with those wireshark files?
0
 
LVL 14

Expert Comment

by:JAN PAKULA
ID: 39267988
not sure what was your sonicwall ips - but it would be all with tcp checksum offloading problem" (black ones)
0
 

Author Comment

by:maximus7569
ID: 39278351
ok thanks.  Looks like we have not had any issues so far. You were very helpful.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
firewall inside of network 9 73
Multiple Static IP addresses on Router 14 105
Watchguard XTM 2 70
Cisco ASA policy-map not matching the specific traffic 3 52
Having worked with technical  professionals (tech communication) ranging from top IT executives to Ivy League scientists to internationally ranked engineers,  I fancy myself a cocktail party technologist – I understand enough about a wide spectrum o…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now