We help IT Professionals succeed at work.

Terminal Server processing numerous packets from a single external connection

Kirchtoe
Kirchtoe asked
on
178 Views
Last Modified: 2017-04-04
I have a 2012 R2 Terminal Server used for Remote Desktop connections.  We have been experiencing slow connections and cutoffs throughout a given day so I decided to investigate.

When I connect to the server and run, for example, Wireshark to see what is hitting the NIC, I see that in a 10-second capture there are maybe 800 packets coming from my public IP.

No other remote connection shows anywhere near this many packets.  This behavior doesn't seem normal.

I have attached a file showing the packet capture from Wireshark.  72.135.233.88 is my public IP.
Network-capture.docx
Comment
Watch Question

Elango SathyadevSenior Systems Engineer

Commented:
From what i see it could be DNS.

Is your internet provider Spectrum Internet with organisation name "Time Warner Cable Internet LLC"

Change wireshark to all origin and destination port and post the capture again.

In Wireshark go to Edit -> Preferences -> Columns add the ports
CERTIFIED EXPERT
Commented:
This problem has been solved!
(Unlock this solution with a 7-day Free Trial)
UNLOCK SOLUTION