Hi Jon,
A dropped connection I believe will have the following characteristics in terms of TCP flags (Flags ........ ACK PSH RST ), thus the following I believe will capture what you are looking for:
- /TRADD
- New TCP Trace
- Definition will look like follows:
Page 1 (Can get more specific if you wish)
Name ............... DROPPED
Description ........ dropped
Trace Packets with:
TCP/IP Stack .......+ TCPIP
Interface Name .....+
Local Host ..........
Local Ports .........
Foreign Host ........
Foreign Ports .......
Page 2:
After the Initial Packets, Trace Packets with:
TCP Flags .......+ ACK AND PSH AND RST
Give that a shot and let me know.
Thanks,
Steve