The complaint came in that it was taking from 4 to 20 minutes to transfer data.
Why is the network slow? Is it the network?
Could it be the infamous SNAIL problem?
At first the client sent me a trace only from the client side. The trace file showed packets out of order and some re-transmissions along with low TCP windows. I asked the client if it was possible to get a capture from both sides, client and server and the answer was “yes” (In my world that is the best way to eliminate any magic!)
First: I looked at the server side trace file first. It showed the server re-transmitting over a thousand times. (Uh Oh)
By having both sides I was able to prove that the server did indeed send the packet but the client did not receive it.
We can also see that they are 5 hops from each other, which means something is dropping packets.
Next : It is time to interrogate router interfaces and firewall interfaces for discards or drops.
Watch this Video for the problem visibility process, guiding us to the issue at https://youtu.be/WW0SjeeteK8
Get a TAP to see every bit of your Data!