# Bro behind a TLS reverse proxy

**URL:** <https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5249>\
**Category:** Zeek\
**Created:** [April 10, 2018, 3:57pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5249 "2018-04-10T15:57:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![promerocenic](https://avatars.discourse-cdn.com/v4/letter/p/2acd7d/32.png) [@promerocenic](https://community.zeek.org/u/promerocenic)\
**Post date:** [April 10, 2018, 3:57pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5249/1 "2018-04-10T15:57:16Z")

</div>

FYI - I was able to run the test commands on a VirtualBox VM and the results show that the date appears correct.

$ tshark -t ud -r lo-port-80.pcap  
1 2018-04-10 15:36:12 ::1 → ::1 TCP 94 37816 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65476 SACK\_PERM=1 TSval=4294908231 TSecr=0 WS=128  
2 2018-04-10 15:36:12 ::1 → ::1 TCP 74 http \> 37816 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0  
3 2018-04-10 15:36:12 127.0.0.1 → 127.0.0.1 TCP 74 32966 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK\_PERM=1 TSval=4294908231 TSecr=0 WS=128  
4 2018-04-10 15:36:12 127.0.0.1 → 127.0.0.1 TCP 54 http \> 32966 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0  
$

Philip

---

<div class="post-metadata">

**Author:** ![Brandon\_Sterne](https://avatars.discourse-cdn.com/v4/letter/b/58956e/32.png) [@Brandon\_Sterne](https://community.zeek.org/u/Brandon_Sterne)\
**Post date:** [April 10, 2018, 5:57pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5249/2 "2018-04-10T17:57:08Z")

</div>

Hi Philip,

I’m not sure what differs between your environment and mine. On my VirtualBox C7 box I see the bad packet (pcaps attached):  
[vagrant@localhost ~]$ sha1sum pcaps/lo-port80.pcap  
6f44be24c1491ddf4285c6e4c585fc1d8b307439 pcaps/lo-port80.pcap  
[vagrant@localhost ~]$ tshark -t ud -r pcaps/lo-port80.pcap | head -n6  
1 2018-04-09 23:16:28 ::1 → ::1 TCP 94 58156 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65476 SACK\_PERM=1 TSval=8358348 TSecr=0 WS=64  
2 2018-04-09 23:16:28 ::1 → ::1 TCP 74 http \> 58156 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0  
3 2018-04-09 23:16:28 127.0.0.1 → 127.0.0.1 TCP 74 43060 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK\_PERM=1 TSval=8358349 TSecr=0 WS=64  
4 1971-02-20 11:53:55 127.0.0.1 → 127.0.0.1 TCP 74 http \> 43060 [SYN, ACK] Seq=0 Ack=1 Win=43690 Len=0 MSS=65495 SACK\_PERM=1 TSval=8358349 TSecr=8358349 WS=64  
5 2018-04-09 23:16:28 127.0.0.1 → 127.0.0.1 TCP 66 43060 \> http [ACK] Seq=1 Ack=1 Win=43712 Len=0 TSval=8358349 TSecr=8358349  
6 2018-04-09 23:16:28 127.0.0.1 → 127.0.0.1 HTTP 139 GET / HTTP/1.1

I ran another test today on C7 bare metal, and this time I saw a problem with the first SYN-ACK packet, but this time the timestamp was far in the future:  
[brandon.sterne@s-mxq61403r3 pcaps]$ sha1sum lo-port-80-bm.pcap  
20dbe8f5e67668ef1f6e37724910470cd4e47d74 lo-port-80-bm.pcap  
[brandon.sterne@s-mxq61403r3 pcaps]$ tshark -t ud -r lo-port-80-bm.pcap | head -n6  
1 2018-04-10 17:13:22 ::1 → ::1 TCP 94 53636 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65476 SACK\_PERM=1 TSval=3967522213 TSecr=0 WS=128  
2 2018-04-10 17:13:22 ::1 → ::1 TCP 74 http \> 53636 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0  
3 2018-04-10 17:13:22 127.0.0.1 → 127.0.0.1 TCP 74 42944 \> http [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK\_PERM=1 TSval=3967522213 TSecr=0 WS=128  
4 2061-07-14 21:16:16 127.0.0.1 → 127.0.0.1 TCP 74 http \> 42944 [SYN, ACK] Seq=0 Ack=1 Win=43690 Len=0 MSS=65495 SACK\_PERM=1 TSval=3967522213 TSecr=3967522213 WS=128  
5 2018-04-10 17:13:22 127.0.0.1 → 127.0.0.1 TCP 66 42944 \> http [ACK] Seq=1 Ack=1 Win=43776 Len=0 TSval=3967522213 TSecr=3967522213  
6 2018-04-10 17:13:22 127.0.0.1 → 127.0.0.1 HTTP 139 GET / HTTP/1.1

Do others see anything like this? I appreciate any help you can offer in reducing the testcase and identifying the offending software.

Best,

Brandon

[lo-port-80-bm.pcap](https://community.zeek.org/uploads/short-url/4GGqUwTlfwDHIVfsEy33miFyc4c.pcap) (2.44 KB)

[lo-port80.pcap](https://community.zeek.org/uploads/short-url/fSkhlQYKOGBveCd77x2ERiIbNW1.pcap) (2.65 KB)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5249/3 "2022-05-06T15:45:41Z")

</div>


