cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3856
Views
0
Helpful
2
Replies

mass "tcp dup ack" in wireshark capture

xiaoliangyue
Level 1
Level 1

Hi,

the users experience significant slow Citrix performance. Citrix server's ip is 192.168.1.4. I setup span on switch, and captured packets via Wireshark. in the packets, I notice some tcp duplicate ack, e.g. since #428. Could this indicate something? by the way, 192.168.1.3 is a file server.

thanks,

Jon

2 Replies 2

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Jonathan,

this can come from the way you have configured the monitor session:

if the source is a vlan and you receive both tx and rx each packet is seen twice on the sniffer one for the port that receives it one for the port that sends out it.

This shouldn't be a sign of a real problem.

I've examined some packet captures few days ago and they showed the same massive tcp dupl. but this was not real in my case.

Hope to help

Giuseppe

the source is Citrix server interface only, both tx & rx.

thanks, Giuseppe!

Review Cisco Networking products for a $25 gift card