02-01-2012 01:05 AM
Hi,
I'm running product version 18.6.0.29 One Click Support appears to stick on "Checking Updates". Running a packet capture the application appears to direct the traffic to IP 216.82.243.91. However the server on this IP address responds constantly with [TCP Window Update]. (see below)
117.168716216.82.243.91192.168.206.133 TCP 60 https > syscomlan [ACK] Seq=1 Ack=1461 Win=1460 Len=0
127.169005 216.82.243.91 192.168.206.133 TCP 60 [TCP ZeroWindow] https > syscomlan [ACK] Seq=1 Ack=2921 Win=0 Len=0
137.209628 216.82.243.91 192.168.206.133 TCP 60 [TCP Window Update] https > syscomlan [ACK] Seq=1 Ack=2921 Win=1460 Len=0
147.209759 192.168.206.133 216.82.243.91 TCP 1514 [TCP segment of a reassembled PDU]
157.209907 216.82.243.91 192.168.206.133 TCP 60 [TCP ZeroWindow] https > syscomlan [ACK] Seq=1 Ack=4381 Win=0 Len=0
167.302242 216.82.243.91 192.168.206.133 TCP 60 [TCP Window Update] https > syscomlan [ACK] Seq=1 Ack=4381 Win=2920 Len=0
177.302320 192.168.206.133 216.82.243.91 TCP 1514 [TCP segment of a reassembled PDU]
This appears to run constantly with the same responce from the server. DNS query's are:
417.472297 192.168.206.133192.168.206.2 DNS 81 Standard query A tificocs.symantec.com
607.578137 192.168.206.2192.168.206.133 DNS 448 Standard query response A 204.232.134.16
84417484.395253 192.168.206.133192.168.206.2 DNS 88 Standard query A backup.sp1.symanteccloud.com
84696485.108623 192.168.206.2192.168.206.133 DNS 236 Standard query response A 216.82.243.91
The One Click Support does not update.
Any guidance will be great.
02-01-2012 01:29 AM
Conversation from the tificocs.symantec.com server below:
279105.397540 192.168.206.133 192.168.206.2 DNS 81 Standard query A tificocs.symantec.com
282107.609061 192.168.206.2 192.168.206.133 DNS 97 Standard query response A 204.232.134.16
283107.704110 192.168.206.133 204.232.134.16 TCP 62 ddt > https [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1
286110.636795 192.168.206.133 204.232.134.16 TCP 62 ddt > https [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1
287110.637020 204.232.134.16 192.168.206.133 TCP 60 https > ddt [ACK] Seq=1 Ack=1 Win=64240 Len=0
288116.714277 192.168.206.133 204.232.134.16 TCP 62 ddt > https [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1
289116.721054 204.232.134.16 192.168.206.133 TCP 60 [TCP Dup ACK 287#1] https > ddt [ACK] Seq=1 Ack=1 Win=64240 Len=0
300128.648461 204.232.134.16 192.168.206.133 TCP 60 https > ddt [RST, ACK] Seq=1 Ack=1 Win=64240 Len=0
Server responds with a [RST, ACK]... Popup stays on "Checking Updates" No further packets are sent.
84417484.395253 192.168.206.133192.168.206.2 DNS 88 Standard query A backup.sp1.symanteccloud.com
84696485.108623 192.168.206.2192.168.206.133 DNS 236 Standard query response A 216.82.243.91
Backup Exec appears to be backup updates.
