Quote from: deanwebb on May 10, 2018, 09:10:09 AM
I don't know why people put off getting the packet capture... it's going to work, it's going to solve the problem, it's going to be the best thing you do all day. So why waste time with anything else?
I submit that the people that don't go directly to setting up a capture are either just being lazy, don't know how to do it, or are a combination of the two.
Lazy I can't help.
Not knowing how to do it? Google up "tcpdump", load Wireshark, and get busy.
Just had a case yesterday, lots of finger pointing, everybody blaming everyone else. The arguing had been going on for HOURS. I got parachuted in and asked the question, "What does the packet capture show?"
Silence.
Next thing I said was, "Get the packet capture on the server and it will show if there's any attempt to connect with the remote host."
They got the packet capture.
One hour later, they had the fix in place.
If they had gone for the capture instead of the political posturing bullcrap, they would have had the fix, less arguing, and no need to make everyone mad with accusatory finger-pointing.
Evidence based assessment? Blasphemy!!!