On Wed, Feb 23, 2022 at 07:04:15PM -0600, Justin Pryzby wrote: > And the aforementioned network trace. You could set a capture filter on TCP > SYN|RST so it's not absurdly large. From my notes, it might look like this: > (tcp[tcpflags]&(tcp-rst|tcp-syn|tcp-fin)!=0) I'd also add '|| icmp'. My hunch is that you'll see some ICMP (not "ping") being sent by an intermediate gateway, resulting in the connection being reset. -- Justin