Out of order packets via LWAPP?

I am capturing packets on a wireless client ftp'ing a file from a server. It's showing that there are a lot of out of order packets. Although, the file received is fine, I'm worried that it'll affect voice packets later on. I'm using Wism with Lightweight APs. I tested using autonomous AP to tranfer the file from the same server--> No problems. Any ideas why this is? Is it some thing I mis-configure on the WLC?
Thanks
Binh Dinh

Good mornning.
We have many application similar to the case you have explained.
Our links use satelite connection and the delayare between: 600 msec to 1000 msec.
Delays over 1000 msec generates delay and connectivitiy problems with tcp applications.
What is the delay between your endpoints ?
Do you have access to internet router ? so can you tell us if there are packets drops in the interfaces ?
Waiting your answer.

Similar Messages

  • Strange out of order packet issue

    Not sure if this is the proper place to ask this or not, but I have an odd issue with a VM (really multiple VMs but they all do the same thing).  The VMs run RHEL 6.5 and spool a print job to a printer at the far end of a WAN connection.  The printer doesn't handle out of order packets correctly and ultimately just waits for the OS to decide it should resend things and restart.  This causes major delays in the print job.  The app was migrated from a RHEL5.10 physical system to the VM where the problem started.  The printer vendor has admitted a problem in the way they handle out of order packets but isn't fixing it in the printer(s) we have.  When the app was on RHEL5/physical system the problem did not occur.  At least, it wasn't severe enough for us to look really deep into.  The application team wants to move back to RHEL5/physical until the problem is resolved but I am reluctant to do that because it effectively means they won't migrate into a VM for another 1-2 years.
    I think a previously existing problem is being made worse by the VMware layer, but don't know what I can do about it.  We run the Nexus 1000V with LACP back to redundant Nexus 7000's before the connection routes to the WAN circuit.  I have been told the problem can be reproduced without going thru the WAN, and we have tried using the VSS on a separate pair of cables, but it didn't help.  Can anyone think of anything that I can check or tweak to make things easier for my end users?  I really don't want to move back to physical.  It makes so many processes 10x more difficult.
    We are running ESXi 5.5u2 with vSphere 5.5u2 on IBM 3850m3 servers.  They aren't memory, CPU, or disk constrained at all as far as anyone can tell, and the network from the box isn't saturated or that busy at all.
    Thanks.
    Tom

    Thanks.  I had seen something on that earlier but hadn't looked into it.  I made the change on one of our problem children, so we'll see what happens now.
    Is that persistent across reboots or is there some file I need to change as well?
    Tom

  • TCP out of order packets

    Hi,
    We are getting TCP out of error packets while sending requests to outside. Though we can access the internet and also connectivity is fine. But some of the application is not working due to this error, specially TCP based application as on the remote side they are not accepting two requests from our network. That means two requests are going from our network with each of the request sent to outside network.
    We have 4-5 vlans and intervlan routing is configured. Could somebody pls. let me know the reason of this and how can I solve this problem?
    Thanks,
    Pawan

    Good mornning.
    We have many application similar to the case you have explained.
    Our links use satelite connection and the delayare between: 600 msec to 1000 msec.
    Delays over 1000 msec generates delay and connectivitiy problems with tcp applications.
    What is the delay between your endpoints ?
    Do you have access to internet router ? so can you tell us if there are packets drops in the interfaces ?
    Waiting your answer.

  • Help with TCP out-of-order packets Wireshark capture

    Hello everyone,  we have a bit of an odd issue. Can you take a look at the attached capture file and tell me what's broken? Please change the file extension from .txt to .pcapng and open with Wireshark. 
    We have a major issue where clients cannot retrieve data from the server at 10.10.7.27.
    Server is behind the firewall at 172.18.123.4 which is configured to NAT the traffic coming through.
    Please advise.

    It's actually from anywhere.  The DNS resolves the website address to a global address.  So regardless of the source (inside or out), you hit the firewall and get routed to 10.10.7.0 network.  The firewall's LAN interface shares the same VLAN as the DMVPN head-end router's LAN interface.  From the DMVPN head-end router, it goes over the DMVPN cloud (i.e. back over the internet) to our office in Florida where this site is being hosted. 
    The capture I grabbed was by SPAN port between the two LAN interfaces showing transactions between the firewall's LAN interface and the server's IP address on the 10.10.7.0 subnet.
    Site uses HTTPS and we have other servers in the same subnet (10.10.7.0) that are accessible in the same manner.  I did SPAN the ports for another webserver and did see a lot of TCP OOO and re-transmissions however not as bad as this one. 
    I do have a theory, please feel free to correct me.  Request comes in on the WAN interface, gets NATed by the firewall and sent to the DMVPN router, router encrypts the packet and places it on the wire, once the remote DMVPN peer receives the packet, it decrypts it and then sends it out it's DMZ interface connected to another application firewall. This firewall checks the packet and then sends it to the web server hosting the content.  The process is reversed for reply traffic. On top of all this, the content is served over HTTPS therefore more encryption/decryption. This seems like too much handling of the packet to me?  When the source computer sends a request, it simply times out or spends too much time within our own network causing the source to resend the request?

  • TCP out-of-order at IPS

    Dear All,
    We have a setup the IPS 4510 working inline mode with strict inspection turn on. we have detected some latency issue accessing the internal website. So we did some capture at the IPS interface. We found that there's a lot of out-of-order packet and DUP ACK detected by IPS which causing the normalizer engine buffer full and could not handle anymore request. As a work around we put the IPS in asymmetric mode where it turn off the IPS normalizer engine. 
    I need some opinion on possibilities why the Out of order and DUP ACK happen. 
    We are seeing quite a lot of Out-of-order, DUP ACK and TCP zero window in TCP stream that we captured. 
    The topology is quite straight forward:
    Internet ----WAN ROUTER ----- IPS4510 ----- ASA ----- Web server
    There's no redundancy or load balance for the ASA or WANROUTER. 
    Im hoping for some opinion and idea on how to tackle this issue.
    Thank you very much

    Hi
    bumping out an old thread since the issue still on going.
    I already discussed with TAC regarding the issue and 2 option that she gave
    + asymmetric mode (Which we rejected as permanent solution)
    + Event action filter
    I'm currently looking at this solution and plan to implement it in the IPS.
    I need to consider a few things and also suggestion
    + The signature engine involve is Normalizer engine (specifically sig 1330)
    + is it possible to customize this signature or should we just go for Event action filter?
    need opinion and pro and cons of this.
    Thanks a bunch

  • ACE Dup ACK and TCP Out-of-order

    Hi,
    I have a pair of FT ACE 4710 offloading https traffic to a couple of webservers. We are seeing very high network utilisation when I capture the client facing port of the active ACE. There appears to alot of duplicate ACKs and TCP out-of-order packets (as shown by wireshark). Does anyone know if this is a problem with the ACE or "normal"
    Thanks

    I've seen some similar behaviour with the ACE Module and Apache webservers. To mitigate this I've configured the following which seems to work.
    On the ACE Module
    parameter-map type http ALL-HEADERS
      persistence-rebalance
    parameter-map type connection TCP-OPTIONS
      set tcp syn-retry 5
      tcp-options timestamp allow
    policy-map multi-match test-policy
      class http-vip
        loadbalance vip inservice
        loadbalance policy http-test-pm
        loadbalance vip icmp-reply active
        appl-parameter http advanced-options ALL-HEADERS
        connection advanced-options TCP-OPTIONS
    On Apache here are the two test results with keepalive on and off
    httpd.conf
    KeepAlive Off
    MaxKeepAliveRequests 1024
    KeepAliveTimeout 30
    MK-ACE01/001# show serverfarm MK-FARM-sf
    serverfarm     : MK-FARM-sf, type: HOST
    total rservers : 8
                                                    ----------connections-----------
           real                  weight state        current    total      failures
       ---+---------------------+------+------------+----------+----------+---------
       rserver: MK-HOST10
           10.10.1.10:0          8      OPERATIONAL  321        510863     16442
       rserver: MK-HOST11
           10.10.1.11:0          8      OPERATIONAL  304        512718     16276
       rserver: MK-HOST12
           10.10.1.12:0          8      OPERATIONAL  286        524207     17257
       rserver: MK-HOST13
           10.10.1.13:0          8      OPERATIONAL  291        516987     16626
       rserver: MK-HOST14
           10.10.1.14:0          8      OPERATIONAL  291        513016     16594
       rserver: MK-HOST15
           10.10.1.15:0          8      OPERATIONAL  311        510177     16434
       rserver: MK-HOST16
           10.10.1.16:0          8      OPERATIONAL  345        516340     16708
       rserver: MK-HOST17
           10.10.1.17:0          8      OPERATIONAL  282        513046     16418
    httpd.conf
    KeepAlive On
    MaxKeepAliveRequests 1024
    KeepAliveTimeout 30
    MK-ACE01/001# show serverfarm MK-FARM-sf
    serverfarm     : MK-FARM-sf, type: HOST
    total rservers : 8
                                                    ----------connections-----------
           real                  weight state        current    total      failures
       ---+---------------------+------+------------+----------+----------+---------
       rserver: MK-HOST10
           10.10.1.10:0          8      OPERATIONAL  0          553        0
       rserver: MK-HOST11
           10.10.1.11:0          8      OPERATIONAL  0          551        0
       rserver: MK-HOST12
           10.10.1.12:0          8      OPERATIONAL  0          552        0
       rserver: MK-HOST13
           10.10.1.13:0          8      OPERATIONAL  0          555        0
       rserver: MK-HOST14
           10.10.1.14:0          8      OPERATIONAL  0          554        0
       rserver: MK-HOST15
           10.10.1.15:0          8      OPERATIONAL  0          551        0
       rserver: MK-HOST16
           10.10.1.16:0          8      OPERATIONAL  0          550        0
       rserver: MK-HOST17
           10.10.1.17:0          8      OPERATIONAL  0          550        0
    This seems to of reduced the large number or re-transmits and dup-acks.

  • Sales Order Entry via Portal in R/3 4.7

    Hi,
    is there an iView (out of a Business Package) available for Sales Order Entry via Portal in R/3 4.7 ?
    Or do we need to develop this from scratch?
    Thanks & Regards,
    Erik

    Hi Erik,
       The only one I found was in the Business package for Sales but it is listed for ERP2004 only.  I found another one in the Business Package for Retail 50.2 that was 4.7 compatible but it is shown as out of maintenance and I was unable to download it. I didn't try very hard to get the download to work.  You may want to take a look.
    Good Luck,
    John

  • "Keys out of order" message in Disk Utility

    Hi,
    I was just doing a regular maintenance check with Onyx and to my surprise it said I needed to repair the disk using the Installer DVD and Disk Utility.
    I did this and again to my surprise I seem to have a problem.
    After the whole processs is complete these messages come up:
    "keys out of order" (in red)
    1 HFS Volume repaired (in green)
    1 Volume could not be repaired (in red)
    I don't know what to do about this. On the one hand my system seems to be running fine, but on the other if these errors are coming up then surely there is an issue which I need to resolve.
    Could someone enlighten me on what to do next?

    Hi,
    Thanks. Unfortunately my battey died and now I am stuck on the apple logo at reboot. Opening disk utility via the install disk doesn't work as disk utils doesn't recognise any disks (even though I hear them spinning)
    I am lucky in that I am able to access th powerbook's HD in target mode via firewire on my G5
    so I am going to copy over a lot of my data and then invest in Diskwarrior.
    However, I am a little confused with the Diskwarrior website. I would prefer to download as I am not near a shop to buy the software and I would rather not pay for express amazon delivery.
    Would I be able to use the download of diskwarrior on my Powerbook?
    It seems a little confusing:
    "If You Are Purchasing DiskWarrior
    Repairing your usual startup disk requires that you start up from another disk. In order to use the download copy of DiskWarrior, you will need to start up from another disk with Mac OS X 10.3.9 through 10.4.x installed. You will then need to run a copy of DiskWarrior from a disk that is not the disk you are repairing. (The DiskWarrior download does not include the Apple System files necessary to create a startup CD.) If you cannot use the download version of the software (i.e. you have only one internal hard drive and this is the drive you wish to repair), please order directly from our sales department or from one of our resellers to be sent the software on CD. If you order via the secure server, you will be sent a CD, but delivery of your CD will take approximately three to four weeks, depending on your location."
    Basically I am in a hurry to get my Powerbook working by Thursday my two options are
    a)Buy from Amazon and pay extra to get express delivery by wednesday
    b)Buy download from Alsoft (with cd version on way in 2-3 weeks)....however if the download version is not sufficient then i'm screwed.
    I'd really appreciate help here. It just happens that I have to work away on Thursday....and I therefore need my powerbook. I usually use my G5 in my home studio.
    THANKS!!
    Message was edited by: recall

  • Gmail dates out of order

    I recented moved from an exchange server to Gmail utilizing IMAP. The problem is that my emails are not in date order on my iphone 5s 7.1 (problem still existed under 7.0.6), but they appear perfectly in Gmail via web, Outlook, and Apple Mail. I can't seem to figure out what order they are actually in. I have exposed the date fields in outlook like date create, modified, received, sent, etc, but even ordering on any of those doesn't explain the sort order on the iPhone.
    Thanks for any input!

    Hello Omar12345
    Have you tried removing your email account and then add it back in to Mail. Also have you tried using the Gmail app to see if it works there?
    iOS: Troubleshooting Mail
    http://support.apple.com/kb/ts3899
    Gmail - email from Google
    https://itunes.apple.com/us/app/gmail-email-from-google/id422689480?mt=8
    Regards,
    -Norm G.

  • I have to send the sales order output via mail to a customer

    have to send the sales order output via mail to a customer, what steps i have to follow
    kindly guide me.
    regards
    satya

    Hello,
    You need to carru out your output configuration for this.
    Use tcode, NACE where you can do this centrally.
    Select V1 & click on output types above
    Select output type MAIL for your requirement & use tranmission medium as simple mail.
    After configuring your MP mail partner functions & use of proper output program you will be able to send mail to your party.
    Hope this is helpful to you.
    Regards,
    Dhananjay

  • Out-of-order-writing and fsync issues ...

    I am facing a fairly interesting problem on my Sun box.
    The problem is: My customer has reported that PostgreSQL loses a file on TRUNCATE.
    The scenario is:
    BEGIN;
    TRUNCATE table;
    COMMIT;
    When the system is killed during this transaction it can happen that the system tables will still see the table while the file on disk is already killed.
    However, this is impossible because the table is actually killed by PostgreSQL AFTER the COMMIT.
    Internally it does:
    BEGIN;
    modify system tables;
    COMMIT (including fsync)
    remove table on disk.
    The problem now is: How than this happen? The only thing which comes to my mind is that the I/O system is doing out-of-order writing. My second theory is that fsync is doing something terribly wrong. More evidence: This happens not too frequently and ONLY on Solaris (We have tested that).
    Can anybody provide me information about the I/O behaviour of the kernel respektively information about what fsync might do wrong?
    Help is very much appreciated.
    Best regards,
    Hans

    Hi there! @BlueSkies84 thanks for posting your concerns. I’m sorry to hear about all the problems with your phone.
    Since we are looking at multiple issues that cannot be controlled via the phone settings, I’d recommend you back your phone up and perform a factory reset. For steps on this please visit us at www.att.com/devicehowto/ and select the make and model of your phone. On the left column you’ll find steps to back up the phone under backup and restore and reset steps under troubleshooting and reset device.
    Hope this helps!
    Charise

  • Signature 1330-X: TCP segment out of order - what does it mean?

    Hi,
    on a customer's site, on one of their IPS, I get a lot of sig 1330 alerts, mainly those two:
    1330-12: TCP segment is out of order. If the signature status is set to disabled, the packet will be passed to all engines that are not stream based.
    This signature will not produce an alert in promiscuous mode regardless of the signature status.
    1330-17: TCP segment out of state order. If a packet in a stream causes this signature to produce an alert, processing will cease for that stream. This signature will not produce an alert in promiscuous mode regardless of the signature status
    I'm not sure how to interpret these alerts correctly and/or how to troubleshoot further. Does anyone have an idea?
    Thanks a lot,
    Florian

    Is your sensor monitoring more than one network segment?
    If so then these alarms are common when a TCP connection crosses both networks and gets seen twice by the sensor.
    This can confuse the sensor's tracking of the connection.
    A common scenario is to have the sensor monitor both the Inside network or a firewall as well as the DMZ. When an internal user connects to the company's web server the traffic gets seen by the sensor both on the Inside network and in the DMZ. The sensor tries to put the packets from both networks together in order to try and monitor it as a single connection. Because the packets get modified by the firewall it often results in inconsitency between traffic on the 2 sides and causes the sensor to be confused about the connection.
    The good news is that if this is your problem, then there are 2 easy workarounds.
    1) If your sensor supports virtual sensors, then create a second virtual sensor. Assign one network to default vs0, and assign the other network to the new virtual sensor. This way each virtual sensor sees traffic on just one of the networks and won't become confused.
    2) If your sensor does not support additional virtual sensors, or you've used up all 4 virtual sensors, then there is a configuration option within the virtual sensor configuration itself:
    Inline TCP Session Tracking Mode
    By default it is set to Virtual Sensor which is why it tries to put together packets from both networks to try and look at is a single connection and gets confused.
    BUT it can also be set to Interface and Vlan. This configuration allows the virtual sensor to treat the traffic on each network independantly. The connection on the first network will be monitored independant of the connection on the second network. This will prevent the virtual sensor from getting confused.
    The above is just my guess at what is going on in your network based on what we've seen on other networks. If this doesn't address the reason for the signature triggerings, then please respond back with more information about your network.
    It is possible that these could be a hacker trying to avoid detection by the sensor, but more likely something in your deployment is confusing the sensor.

  • Texts out of order; phone overheating; speaker issues

    Hi, I am having four problems with my Galaxy S5 and wondered if anyone knew a solution: (1) My text messages come out of order.  This has happened since I got the phone, which is on network time. (2) My text messages are delayed - both sending and receiving.  They get to others late and they come to me late. (3) My phone frequently gets extremely hot and the battery drains rapidly.   From 95% to 15% in an hour or two. (4) When I am talking on the phone, the phone randomly switches to speakerphone so the person I am talking to comes out of the speaker.  The speaker button, however, is not activated.   Many thanks for any help! 

    Hi there! @BlueSkies84 thanks for posting your concerns. I’m sorry to hear about all the problems with your phone.
    Since we are looking at multiple issues that cannot be controlled via the phone settings, I’d recommend you back your phone up and perform a factory reset. For steps on this please visit us at www.att.com/devicehowto/ and select the make and model of your phone. On the left column you’ll find steps to back up the phone under backup and restore and reset steps under troubleshooting and reset device.
    Hope this helps!
    Charise

  • Sales orders received via EDI

    Any idea of the table/field from where i can find out the all the sales orders received via EDI?

    hi;
    EDIDC is the table where in you will find all the Idocs that have come into the system. This is also the table which would give the info abt the Idocs that have been sent out of the system.
    EDID4 is the table where in you will find the idocs that have gone into error.
    Regards.

  • /etc/sshd_config out of order?

    Leopard has this new GUI feature for allowing only certain users to connect via ssh. On Tiger I used /etc/sshd_config with the AllowUsers directive to define allowed users. The settings in Leopard's System Preferences do not change this file. I gave it a try an added some lines to the sshd_config, but they didn't seem to change system behaviour.
    So, is /etc/sshd_config out of order?
    What file is affected by allowing certain ssh users by System Prefs?
    Hope somebody can shed some light on this …

    Please provide an [url http://sscce.org]SSCCE that demonstrates this.
    Unless you're using a PriorityQueue or some other specialized implementation, it should be a FIFO order. Check the docs for the implementation you're using.
    Edited by: jverd on Nov 22, 2011 4:41 PM

Maybe you are looking for