Proxy Troubleshooting Packet Cheat Sheet

Proxy Troubleshooting Packet Cheat Sheet
Updated
1,284 views

TCP, Retransmissions, Resets, Timeouts, and Proxy-Specific Clues

When troubleshooting proxy issues:

  1. Identify the symptom
  2. Match the packet pattern
  3. Check proxy role (Full Proxy / Half Proxy / L4)
  4. Apply the recommended checks

1️⃣ TCP Handshake Issues

❌ SYN Retransmissions (No Connection Established)

Packet Pattern

Client → Proxy : SYN, Seq=1000
Client → Proxy : SYN, Seq=1000 (Retransmission)
Client → Proxy : SYN, Seq=1000 (Retransmission)

What It Means

  • SYN not acknowledged
  • Connection never established

Common Causes

  • ACL / firewall drop
  • Proxy overloaded
  • Incorrect VIP or routing
  • SYN flood protection triggered

Proxy-Specific Check

  • Full Proxy: Is proxy responding with SYN-ACK?
  • L4 Proxy: Is SYN forwarded to backend?

❌ SYN-ACK Seen, ACK Missing

Client → Proxy : SYN
Proxy → Client : SYN-ACK
(Client never sends ACK)

What It Means

  • Client never completed handshake

Likely Causes

  • Client-side firewall
  • MTU / MSS issue
  • Asymmetric routing

2️⃣ Connection Established but No Data

❌ Handshake OK, No Payload

Client → Proxy : SYN
Proxy → Client : SYN-ACK
Client → Proxy : ACK
(No PSH packets follow)

What It Means

  • TCP established, application stalled

Likely Causes

  • Client waiting on TLS
  • TLS mismatch
  • Application timeout

Proxy Check

  • Full Proxy: TLS handshake logs
  • Half Proxy: TLS passthrough integrity

3️⃣ TLS / SSL Problems (Proxy Termination)

❌ TLS ClientHello Retransmissions

Client → Proxy : ClientHello
Client → Proxy : ClientHello (Retransmission)

What It Means

  • TLS handshake not progressing

Likely Causes

  • Certificate mismatch
  • Cipher incompatibility
  • TLS inspection failure
  • CPU exhaustion (SSL TPS limit)

Proxy Check

  • Certificate chain
  • Cipher overlap
  • TLS version support

❌ ServerHello Never Returns

Client → Proxy : ClientHello
Proxy → Server : ClientHello
(No ServerHello)

Likely Causes

  • Backend TLS misconfiguration
  • mTLS failure
  • Server overload

4️⃣ Retransmissions (Key Proxy Indicator)

🔁 Client-Side Retransmissions Only (Good Sign)

Client → Proxy : PSH, Seq=2001 (LOST)
Client → Proxy : PSH, Seq=2001 (Retransmit)
Proxy → Client : ACK

What It Means

  • Loss isolated between client and proxy
  • Full Proxy working as designed

🔁 Server-Side Retransmissions Only (Good Sign)

Proxy → Server : PSH, Seq=8001 (LOST)
Proxy → Server : PSH, Seq=8001 (Retransmit)
Server → Proxy : ACK

What It Means

  • Backend loss isolated
  • Client unaffected

❌ End-to-End Retransmissions (L4 / Half Proxy)

Client → Server : PSH, Seq=1001 (LOST)
Client → Server : PSH, Seq=1001 (Retransmit)

What It Means

  • No TCP decoupling
  • Loss impacts entire path

5️⃣ Duplicate ACKs

Server → Proxy : ACK, Ack=3001
Server → Proxy : ACK, Ack=3001
Server → Proxy : ACK, Ack=3001

What It Means

  • Packet loss downstream
  • TCP fast retransmit triggered

Proxy Insight

  • Full Proxy absorbs this
  • L4 proxy propagates it

6️⃣ Zero Window / Flow Control Issues

🚫 Zero Window Advertisement

Proxy → Client : ACK, Win=0

What It Means

  • Proxy buffers full
  • Backpressure applied

Common Causes

  • Backend slow
  • Proxy memory pressure
  • Large responses + slow clients

7️⃣ Connection Resets (RST)

❌ Proxy Sends RST to Client

Proxy → Client : RST

Likely Causes

  • WAF policy violation
  • Idle timeout exceeded
  • Backend unavailable
  • Session sync missing during failover

❌ Server Sends RST to Proxy

Server → Proxy : RST

Likely Causes

  • Application crash
  • Backend timeout
  • Server-side firewall

8️⃣ FIN vs RST (Graceful vs Abrupt Close)

✅ Graceful Close

Client → Proxy : FIN
Proxy → Client : ACK
Proxy → Server : FIN
Server → Proxy : ACK

Healthy behavior


❌ Abrupt Close

Proxy → Client : RST

Indicates

  • Policy enforcement
  • Error condition
  • Resource exhaustion

9️⃣ Idle Timeout Issues

❌ Timeout-Triggered Reset

(No traffic for N seconds)
Proxy → Client : RST

Likely Causes

  • Proxy idle timeout too low
  • Long-lived application sessions
  • Keepalive disabled

🔍 0️⃣ How to Identify Full Proxy vs L4 from Packets

Full Proxy Indicators

✔ Different sequence numbers client vs server
✔ Proxy ACKs before server responds
✔ Retransmissions isolated per side

L4 / Half Proxy Indicators

✔ Same sequence numbers end-to-end
✔ Client waits for server ACK
✔ Retransmissions propagate


1️⃣ Quick Symptom → Root Cause Mapping

SymptomLikely Area
SYN retransmitsRouting / ACL / DoS
TLS ClientHello loopCert / Cipher / CPU
RST from proxyPolicy / Timeout
Zero windowBuffer / Backend slowness
High retransmitsNetwork loss
CPU spike + dropsSSL TPS limit

2️⃣ Golden Troubleshooting Order

1️⃣ Check TCP handshake
2️⃣ Check TLS handshake
3️⃣ Check retransmission scope
4️⃣ Check RST source
5️⃣ Check timeouts & buffers
6️⃣ Check proxy CPU / memory


Final Takeaway

Packet patterns never lie.
Once you understand how proxies manipulate TCP, retransmissions and resets become diagnostic signals, not mysteries.

This cheat sheet lets you:

Troubleshoot faster and with confidence

Identify proxy mode from packets

Isolate client vs backend issues

Distinguish network loss from proxy behavior

Disclaimer: This article may contain information that was accurate at the time of writing but could be outdated now. Please verify details with the latest vendor advisories or contact us at admin@sanchitgurukul.com.

Your feedback matters

Was this post helpful?

0 reactions


Discover more from

Subscribe to get the latest posts sent to your email.

1,284 views

Share this article

Help others find this guide.

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading