Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > 3-Way Handshake Issue?

3-Way Handshake Issue?
Thread Tools
Waragainstsleep
Posting Junkie
Join Date: Mar 2004
Location: UK
Status: Offline
Reply With Quote
Mar 21, 2012, 06:54 PM
 
I have a network problem which I've never seen before. Got about 30 machines running on a single 40Mb connection which is nice and fast. The problem is that when surfing the web, you sometimes get pages which are not found. Typically you get a "not found" message from Safari saying it can't find the site. Hitting refresh does nothing, but this can happen to any site at all and a few minutes later it will load just fine, nice and quick, no problem.

Its an intermittent issue, comes and goes and comes again. It varies from site to site, Mac to Mac without any pattern I can discern. Someone suggested that the problem with the remote network sounded like a 3-way handshake failure problem that could be caused by a misbehaving switch. I rebooted both switches just in case with no change.

I was connected to this network for a while earlier over a VPN and noticed I was getting a few issues myself. I had one site load an "It works" page which I think is a default IIS page or something like and this page kept cropping up for other sites afterwards including one or two well-known ones. I was also getting more 404 errors than I should have been. I got around some of these problems by going from Safari to Firefox when it happened which usually seemed to do the trick but after I remembered I was connected to the VPN, I wondered if it was the same issue and started to think it might be a DNS problem. I have no idea how to get a Mac to log its DNS queries and attempted web connections without paying for little snitch or installing a firewall with deep packet inspection.

I have asked one user to change DNS servers and report back. Does anyone have any other ideas?
I have plenty of more important things to do, if only I could bring myself to do them....
     
mduell
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Mar 21, 2012, 07:49 PM
 
The first issue is a known Safari 5 bug. Upgrade to a non-Safari browser.
     
Waragainstsleep  (op)
Posting Junkie
Join Date: Mar 2004
Location: UK
Status: Offline
Reply With Quote
Mar 21, 2012, 07:58 PM
 
It wasn't happening until I switched over to the faster line. Is the bug only present on higher speed networks?
I have plenty of more important things to do, if only I could bring myself to do them....
     
Cold Warrior
Moderator
Join Date: Jan 2001
Location: Polwaristan
Status: Offline
Reply With Quote
Mar 21, 2012, 08:01 PM
 
Is the site doing site to site VPN, or the new line taking some external overhead/encapsulation (PPPoE)? Perhaps an MTU issue.
     
Waragainstsleep  (op)
Posting Junkie
Join Date: Mar 2004
Location: UK
Status: Offline
Reply With Quote
Mar 22, 2012, 05:20 AM
 
The new line is a fibre line. VPN is just my built in OS X client connected to a router on site. The local issue with failing to load pages is the more critical one though.
I have plenty of more important things to do, if only I could bring myself to do them....
     
abbaZaba
Mac Elite
Join Date: Jun 2006
Location: Pittsburgh
Status: Offline
Reply With Quote
Mar 22, 2012, 11:54 PM
 
have you tried switching DNS servers on certain machines while leaving old DNS servers on the others to see if the problem still persists on the machines with different DNS servers?

Does it ONLY happen on Safari or does it pop up after some time using Firefox as well?
( Last edited by abbaZaba; Mar 23, 2012 at 12:24 AM. )
     
Waragainstsleep  (op)
Posting Junkie
Join Date: Mar 2004
Location: UK
Status: Offline
Reply With Quote
Mar 23, 2012, 05:05 AM
 
I had one user change DNS servers but he has yet to report back. I'll chase him up today.
I have plenty of more important things to do, if only I could bring myself to do them....
     
ghporter
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Mar 23, 2012, 06:25 AM
 
It definitely sounds DNS related, particularly because it only started after the change in provider; even if the fibre connection comes from the same ISP used before, their fibre end could be configured very differently from their copper end.

Glenn -----OTR/L, MOT, Tx
     
seanc
Moderator Emeritus
Join Date: Apr 2005
Location: Cambridge, UK
Status: Offline
Reply With Quote
Mar 23, 2012, 02:55 PM
 
Also sounds DNS related to me.
Who is your new provider? What provides DNS resolution in the environment and has this changed?
What new hardware have you installed to cope with this new connection?

If it was a network switch problem, I'd be expecting total connectivity problems on some or all clients.
     
Waragainstsleep  (op)
Posting Junkie
Join Date: Mar 2004
Location: UK
Status: Offline
Reply With Quote
Mar 23, 2012, 04:10 PM
 
Starting to think its my DNS server, though no idea why its doing this. It just provides DNS for services that sit on the clients own domain. Email, web and FTP. Some are local, some are not.
I have plenty of more important things to do, if only I could bring myself to do them....
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 04:05 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,