Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Recent content by Helmuth2

  1. Helmuth2

    Incorrect TCP checksum

    Check if the Checksum Error packets are retransmitted (TCP Sequence number reoccurring). If so this are real errors. regards Helmuth
  2. Helmuth2

    Sniffer Pro

    A few questions to better understand your problem Did the front end not receive the ACK from the database and thus send the retrans? Do you see the ACK of the Database in the trace? If yes what ist the delta time to the Request? src add: 10.204.69.122 (front end app) and dest 10.206.18.13(...
  3. Helmuth2

    Sniffer Portable 4.8 is available now

    Hi, there is another good new feature i was waiting for! It is now possible to specify a wildcard in ip filtering. i.e. 10.20.*.* to capature only a particular subnet. regards Helmuth
  4. Helmuth2

    Sniffer Portable 4.8 is available now

    I've just installed Sniffer portable 4.8 A new feature i really have been waiting for is the realtime decode. NG has a new licencing model. You have to generate a license request file - mail this file to NG - and get an enable file. Until you have enabled the sniffer 4.8 it runs in 15 day trial...
  5. Helmuth2

    'Threadiquette'

    Hi all, as i walk through the threads - i find a lot of old threads which seem to be abandoned by their initiator. We all want to learn in this forum, and therefore i think it is obligatory if there was a helpful tip, to give a positive response in the thread. And also if you found a solution...
  6. Helmuth2

    Decodes

    Hi Fortunat, i think there is a missunderstanding. When i open your file 'eip ope.enc' i only see 11 Frames which do not match at all with your screenshot's in the powerpoint 'eip.ppt' regards Helmuth
  7. Helmuth2

    Dashboard threshold setting?

    Hi Shihlin, there is no basic rule to set these parameters, because every network is different. (switched, shared, nr. of clients, nr. of protocols, etc.). so every network has it's own baseline. A utilisation of 85% may be ok when you are on a switched segment, but it could be a disaster if you...
  8. Helmuth2

    frozen windows source or destination

    Good explanation fortunat! In my opinion this is one of the most stupid expert symptoms, because in 99.9 % there is no problem at all and it makes less experienced troubleshooters investigate in the wrong direction. Best regards Helmuth
  9. Helmuth2

    Decodes

    4.7.5 and looking foreward to 4.8 which they will have hopefully available for download the next couple of days. regards helmuth
  10. Helmuth2

    zero window trigger

    there is one more 'and' condition for the filter at offset 17 Equals 06 (TCP) Protocol - otherwhise you get wrong triggers from ICMP Messages. regards Helmuth
  11. Helmuth2

    zero window trigger

    Here is how you could do it - create a pattern match filter. On a normal IP packet Window Size is at offset 30 length 2 bytes 'anded' with with the IP adress of your server as source address. use this filter then as the event filter on your trigger. Hint: When you create your filter, you can...
  12. Helmuth2

    Decodes

    Hi i was visiting your website and looking at the decode of Ethernet IP IndustrialEtherNet/IP. I wanted to find out what my Sniffer does with this capture file but the file does not match the screenshots of your according powerpoint notes. regards helmuth
  13. Helmuth2

    Sniffer Pro newbie question

    Do you have installed the Sniffer Network drivers for your network card. Maybe your NIC is not in promiscous mode. Do a trace without any filter, if you can't see unicast traffic from this station, either you don't have the correct driver or you are not on a hub. If you do not have much...
  14. Helmuth2

    Sniffer http interpreter - Summary view (4.7 version)

    Hi breizh22, this means that Sniffer sees the continuation of a frame, where the first frame of this transmission is not in the captured data. This could be, that you really havn't captured from the beginning or you have different routes to the receiver and the first packet was traveling this...

Part and Inventory Search

Back
Top