Skip to content

Network Patterns

Malcolm Stewart edited this page Jun 21, 2021 · 16 revisions

Network Patterns

This section contains a number of networking scenarios that you can cross-check with your own traces.

Note: IP addresses and machine names have been obfuscated into the 10.10.xxx.xxx range with generic names, such as SQLPROD01.CONTOSO.COM.

Normal Traces and Fragments

Normal Login Using SQL Authentication
Normal Login Using a Domain Account and NTLM Authentication
Normal Login Using a Domain Account and Kerberos Authentication

Idle Connection with Keep-Alive Packets

[Normal Closing Connection]]
Normal MARS Closing Connection

Abnormal Traces

Connection Dropped in both Directions
Connection Dropped in one Direction
Network Device Reset Connection

Clone this wiki locally