Unexpected ARP response and RST,ACK packet from W5500
Ethernet Chips
No replies yet. Be the first to reply.
Join the discussion.
Ethernet Chips
No replies yet. Be the first to reply.
Join the discussion.
Share projects and connect with makers.
Joined before the site update? first.
New to WIZnet Makers?
We sent a verification link to your address. Open it to activate your account, then log in.
Accounts from this email provider are reviewed by an administrator after verification. Approval usually takes one business day.
Already have an account?
Enter your email address. If it belongs to an account, we'll send a link to set a new password. Members who joined before the site update use this to set their password.
If an account uses that address, we sent a link to set a new password. The link works once and expires in 30 minutes.
Know your password?
Need an account?
RE: Unexpected ARP response and RST,ACK packet from W5500
by Eugeny ·
I think filtered Wireshark output is not enough. If there’re other devices in between (e.g. router, proxy, firewall), they may disrupt the communication and data flow.
At which physical point you gather Wireshark logs - at server? What is the topology of the network? Why Wireshark identifies packet contents as VNC/RFB protocol?
Note that it is server who seems to forget MAC address of the W5500 and asks for it again through broadcast. It may be well not a server, but a router. And this router may have some timeout settings.
RST packet from W5500 Wireshark showing may well come not from W5500, but from some intermediary device, which thinks time is out. And while W5500 does not know about it, it tries transmitting data in packet 27, but as server was already informed by RST, it does not accept this packet (as well as Wireshark labeling it as “spurious” because it is out of TCP protocol).
The best way for you to figure out what is going on:
RE: Unexpected ARP response and RST,ACK packet from W5500
by faberd ·
Hi Eugeny,
Thank you for your quick response.
The wireshark logs are gathered at the server, which is connected via a switch to our internal network. The W5500 is connected to that same switch.
That Wireshark labels our packets as VNC has to do with the port number in use (5500). Using another port marks the packets as ‘regular’ TCP.
Your pointer that some other device could send the messages has proven valuable. After connecting the W5500 to my server using only a hub and no other devices connected, the problem did not occur!
After some more searching and testing we finally cleared up this issue: we had a duplicate MAC address in our network. So both machines were responding to the ARP requests. And ‘the other’ caused the RST,ACK packet to be sent. Changing the MAC address assigned to the W5500 solved it.