Forum Discussion
wendelyes
Jun 11, 2024Altostratus
Hello,
The traffic in the packet captures could be hidden if it is offloaded. This use to happen in fastL4 virtual servers and you can disable it by changing to Standard modifying the fasL4 profile.
Anyway, in this case I would bet that the SYN-ACK is goign through other device and the F5 is not seeing it. The F5 is forwarding the SYN packet and blocking the other traffic coming from the client because the session is not established yet. The reset you have at the end is created by the f5 because the session could not be established.
I think the best way to know where this SYN-ACK is going through is to capture the traffic in the client and check the source mac. This way you can probably check who is sending it.
Regards