DX Application Performance Management

  • 1.  TCP segment of a reassembled PDU

    Posted Apr 30, 2014 08:30 AM

    I run tcpdimp on our network traffic and got through wireshark a lot of TCP traffics with the info TCP segment of a reassmbled PDU.

    The problem is, TIM doesnt seems to analyze the network packets with the message TCP segment of a reassemled PDU. In fact I am not getting any transactions discovered for those packets, even if they containg valid URL info.

    Any advise on how to deal with these type of packets?

    Thanks,

    Luke

     



  • 2.  RE: TCP segment of a reassembled PDU
    Best Answer

    Broadcom Employee
    Posted Apr 30, 2014 03:07 PM

    Your TIM interface is probably oversubscribed/overloaded with data.

    Check with your network team to see how much data is being sent to the TIM. Also ensure you're using Web Filters in CEM.

    Check out the Best Practices documentation provided by Hal German in the Documents directory concerning TIM troubleshooting and setup of your tap/span/vacl.



  • 3.  RE: TCP segment of a reassembled PDU

    Posted May 01, 2014 04:20 AM

    We checked for the TIM CPU and memory usage and they are very low.

    My question is: does the TIM has the handle segmented IP packets?



  • 4.  RE: TCP segment of a reassembled PDU

    Posted May 01, 2014 07:45 AM
      |   view attached

    Can someone explains why CEM can't see the TCP/IP packets in the attached pcap file?

    Please remove the .txt extension before reading with a tool such as wireshark.

    Attachment(s)

    txt
    Packets.pcap.txt   15.01 MB 1 version


  • 5.  RE: TCP segment of a reassembled PDU

    Posted May 01, 2014 08:16 AM

    We think we found the problem: for some network traffic we don't have two ways conversations. We only see packets from the clients to the web servers but not the other way around.

    Thanks,

    Luke