Hi Matt Well this time you have filtered out any SSH traffic on port 22 successfully.
But I'm still only seeing half of the conversation! I see packets sent from client to server. That is from source: 10.194.217.12 to destination: 10.194.217.3 So a different client IP this time And the Duplicate ACK packets (often long bursts) are back in this capture. I've looked at these a little bit more carefully this time, and I now notice it's using the 'TCP selective acknowledgement' feature (SACK) on those packets. Now this is not something I've come across before, so I need to do some googling! SACK is defined in RFC1208. http://www.ietf.org/rfc/rfc2018.txt I found this explanation of when SACK is used: http://thenetworkguy.typepad.com/nau/2007/10/one-of-the-most.html http://thenetworkguy.typepad.com/nau/2007/10/tcp-selective-a.html This seems to indicate these 'SACK' packets are triggered as a result of 'lost packets', in this case, it must be the packets sent back from your server to the client, that is during your video playback. Of course I'm not seeing ANY of those packets in this capture because there are none captured from server to client! I'm still not sure why you cannot seem to capture these packets! Oh, by the way, I probably should advise you to run... # netstat -i ..on the OpenSolaris box, to see if any errors are being counted on the network interface. Are you still seeing the link going up/down in '/var/admin/message'? You are never going to do any good while that is happening. I think you need to try a different network card in the server. Regards Nigel Smith -- This message posted from opensolaris.org _______________________________________________ zfs-discuss mailing list zfs-discuss@opensolaris.org http://mail.opensolaris.org/mailman/listinfo/zfs-discuss