Re: Help needed: TCP Wizards (was 8.0-RC1 NFS client timeout issue)

From: Chuck Swiger <cswiger_at_mac.com>
Date: Mon, 09 Nov 2009 15:45:49 -0800
On Nov 9, 2009, at 3:04 PM, Rick Macklem wrote:
[ ... ]
> It was usually triggered by a server reboot. After the server reboot,
> the server does send an RST to the client. This seems legit, but might
> be what makes Cisco think that "bad things" are happening? (I have no
> access to info about the switches or their configuration, although the
> campus standard is for these ports to be used by a single desktop  
> machine
> only and not a switch or hub.)

The description you've provided suggests your network admins are  
configuring end-user ports with "Port Fast" to avoid the time required  
to do spanning tree learning & detection; they want you to not use a  
switch or hub on such ports to avoid the risk of creating a loop.   
Cisco routers have some options which cause them to drop packets and  
disable the port in such a mode if it sees more than the allowed # of  
ether MAC addresses coming from that port, or if it receives BPDU  
packets indicating that a switch was connected to the port; however,  
this wouldn't cause RST packets to be generated, you'd just lose your  
uplink.

Seeing forged RST packets suggests that something like the Sandvine  
PTS equipment is also around on that network.

Regards,
-- 
-Chuck
Received on Mon Nov 09 2009 - 22:45:50 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:39:57 UTC