• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Malformed syn-ack

Scheduled Pinned Locked Moved Firewalling
16 Posts 4 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cjlambiii
    last edited by Sep 9, 2019, 11:41 PM

    No switching issues or IP conflicts. I am able to get to the management UI of pfsense on that same nic. Which tells me TCP works on the RPI. UDP and ICMP work perfectly to destinations on the other side of the firewall.

    This is the only node on this network aside from pfsense.

    1 Reply Last reply Reply Quote 0
    • C
      cjlambiii @KOM
      last edited by Sep 9, 2019, 11:44 PM

      @KOM said in Malformed syn-ack:

      TCP retransmissions are a symptom of the problem and not the cause. It could be cable, port, duplex mismatch...

      Your capture shows the initial SYN from your server, and the top capture shows that it gets a SYN ACK back, but it doesn't reply with an ACK to finish the handshake (or at least not in the snippet you showed), so each end starts retransmitting. Do you have an IP address conflict, packet storm or switch loop going on? He's retransmitting his SYN ACKs, and you're replying with SYNs as if you're trying to start the handshake.

      Those syn-acks are becoming rx_errors on the RPI which makes me think they are malformed packets.

      1 Reply Last reply Reply Quote 0
      • K
        KOM
        last edited by Sep 9, 2019, 11:59 PM

        Do a capture on pfSense LAN to see how those packets are leaving the interface to your Pi. Try and find where the breakdown happens.

        C 1 Reply Last reply Sep 10, 2019, 12:00 AM Reply Quote 0
        • C
          cjlambiii @KOM
          last edited by Sep 10, 2019, 12:00 AM

          @KOM I already did. :) The syn-ack makes it to the switchport that the RPI is connected to. The RPI doesn't like the packet for some reason. Something is wrong with it.

          1 Reply Last reply Reply Quote 0
          • K
            KOM
            last edited by KOM Sep 10, 2019, 12:07 AM Sep 10, 2019, 12:06 AM

            So the packets are fine out LAN, but are seen as bad after being processed by the Pi NIC...? The traces you showed don't show any bad packets but your NIC stats show receive errors.

            1 Reply Last reply Reply Quote 0
            • C
              cjlambiii
              last edited by Sep 10, 2019, 12:22 AM

              I am beginning to wonder if it is the el'cheapo usb nic that I am using for the LAN interface. I've got a pcie nic arriving tonight.

              The bottom line is this should work with all of the default settings out of the box right?

              1 Reply Last reply Reply Quote 0
              • K
                KOM
                last edited by Sep 10, 2019, 12:24 AM

                Yes.

                1 Reply Last reply Reply Quote 0
                • C
                  cjlambiii
                  last edited by Sep 10, 2019, 2:14 AM

                  It was that miserable USB nic. I put the new pcie nic in and as soon as I powered it back on I was online.

                  1 Reply Last reply Reply Quote 0
                  • C
                    cjlambiii
                    last edited by Sep 10, 2019, 2:16 AM

                    For what its worth it was a Sabernet 10/100 USB nic.

                    1 Reply Last reply Reply Quote 0
                    • D
                      Derelict LAYER 8 Netgate
                      last edited by Sep 10, 2019, 2:23 AM

                      "Don't use USB NICs."

                      "Why?"

                      "Reasons."

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • K
                        KOM
                        last edited by Sep 10, 2019, 1:56 PM

                        Yes, if you would have mentioned that the NIC was USB we would have zeroed in on it immediately. I just assumed you were using the NIC on your Pi.

                        1 Reply Last reply Reply Quote 0
                        16 out of 16
                        • First post
                          16/16
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received