[100238] in RedHat Linux List

home help back first fref pref prev next nref lref last post

tcpdump & ifconfig reporting packets dropping

daemon@ATHENA.MIT.EDU (Fran Fabrizio)
Thu Nov 19 03:07:36 1998

Date: Thu, 19 Nov 1998 02:12:13 -0600
To: redhat-list@redhat.com
From: Fran Fabrizio <fran@primary.net>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com


Hi folks!

I set up a LAN in my house this week to network my two Win9x machines to a
linux box and then the linux box thru a ppp connection to the net.  All
that wors like a charm, the ip masquerading is performing as expected and
everything is hunky dorey.  Almost.

From my Win98 PC, the net moves fast - like it should - the modem doing ppp
is 56k.  http, ftp, telnet, etc... all move pretty speedy.  The problem
arises on my roommate's Win95 machine.  Packets are getting dropped between
his box and the linux box.  Even stranger, they seem to be only http
packets!!!

The output of tcpdump is strange...some packets coming from his machine
looks ok, but some are just jumbles of hex code.  Here is an example of
tcpdump output:

*******************************************************************
20:59:12.311259 69:6d:61:67:65:2f 74:6d:61:70:2c:20 6a70 100:
                         6567 2c20 696d 6167 652f 706a 7065 6720
                         696d 6167 652f 706e 670d 0a41 6363 6570
                         742d 4c61 6e67 7561 6765 3a20 656e 0d0a
                         4163 6365 7074
20:59:18.301259 0:c0:6d:1:ff:3 sap 20 > 0:a0:24:16:5c:4c sap 45 I
(s=0,r=32,C) len=60
                         c203 4000 7f06 42e4 d013 e8ae d0d9 6d14
                         f022 0050 001e 550f 0000 0000 b002 2000
                         d9b0 0000 0204 05b4 0103 0300 0101 0800
                         0000
20:59:18.511259 www.rainorshine.com.http > 192.168.1.3.1057: S
1421451800:1421451800(0) ack 1987856 win 49152 <mss 1460,nop,wscale
0,nop,nop,timestamp[|tcp]> (DF)
20:59:18.511259 pn12-ppp-124.primary.net.61474 > www.rainorshine.com.http: .
ack 1421451801 win 8760 <nop,nop,timestamp 18161 262230> (DF) [tos 0x20]
**********************************************************************
 
Can anyone make any sense of this? ifconfig confirms eth0 dropping packets,
and my own tests show it's only on http requests from his box.  As a
result, of course, his WWW access is somewhere between slow and nonexistent.  

I thoguht it might be the NIC but then why does it work fast with no packet
loss for things like telnet and ping?  So is it an OS setting?  Do MTUs
need to be adjusted?  His machine yused to have a modem and do dialup so I
thought maybe something was configured wrong, but I can't figure it out.
Any ideas would be GREATLY appreciated.

Thanks,
Fran Fabrizio



-- 
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
		http://www.redhat.com http://archive.redhat.com
         To unsubscribe: mail redhat-list-request@redhat.com with 
                       "unsubscribe" as the Subject.


home help back first fref pref prev next nref lref last post