Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall tcpdump showing duplicate packets which were not sent by the client

Hi community,

While troubleshooting an issue with a webservice on an internal network I found out after a packet capture on both the client and the Sophos Firewall (unable to capture on the webservice device) that the Sophos Firewall captures packets which seem not to be sent from the client (duplicate packets).

To make sure that another component in the network set-up was not causing this, I connected the client directly on a free port on the Sophos Firewall. The same for the webservice, I connected it as well on a free port on the Sophos Firewall. The Sophos Firewall is still showing duplicate packets.

Wireshark capture on the client:

 

Tcpdump on the Sophos Firewall:

 

It seems like the Sophos Firewall is duplicating the packets, unfortunately I cannot confirm if the duplicate packets indeed get send to webservice, but it seems to me that this is not normal behavior as must have a sort of performance impact on the client-server or the firewall server.

 Has anybody seen this behavior as well?



Added TAGs
[edited by: Erick Jan at 1:13 PM (GMT -7) on 5 Sep 2024]
Parents
  • Thats OK.

    you can see the packet at different layers ...

    Example: you see the packet on physical interface including VLAN-Tag afterwards within the VLAN interface untagged (and i at the LAG-Interface too ... i see it 3 times ...)

    You may drill into the details and find this little differences. (sequence-number ports and so on are the same ... wireshark say "duplicate")


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • Thats OK.

    you can see the packet at different layers ...

    Example: you see the packet on physical interface including VLAN-Tag afterwards within the VLAN interface untagged (and i at the LAG-Interface too ... i see it 3 times ...)

    You may drill into the details and find this little differences. (sequence-number ports and so on are the same ... wireshark say "duplicate")


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data