TCP Retransmission/HTTPS down NSA 5600
Hi all,
I have an urgent question in regards to TCP traffic issue on our network.
Our clients stay wired/wireless connected, but the browser and all HTTP/HTTPS app down. Ping was working.
We use PRTG monitoring system to monitor. So from the sensors dashboard, the data match what we observed:
HTTP/HTTPS sensors were down at all Switch/AP/clients. Firewall HTTP/HTTPS are up as well as other sensors. In the meantime, the firewall showed some port scans attack detected logs.
It happens a couple of times now.
Has anyone experienced the similar issue? And what could be cause? is it a Firewall or switch issue?
Thanks for taking time to read my post. All discussions are welcomed!
Answers
Hi @MySuperSonic ,
The first thing to do is to run a packet capture on the firewall when the issue is happening to see the packet flow as it will give you some hints on whats going on if its at the firewall level