Friday 22 November 2013

Interpreting TcpDump

1. 14:05:27.083238 ftp.client.org.1057 > ftp.server.edu.21: S 1484414:1484414(0) win 8192 <mss 536,nop,nop,sackOK> (DF)

sequence number of first byte in packet:sequence number of first byte in NEXT packet (data)
(0) = no. of byte

win = TCP available window size advertised by sender

mss = maximum segment size advertised by sender
<mss 536, - an admission by the client that its local network segment can accommodate a packet, without fragmentation, no larger than 536 bytes. 536 bytes is only the size of the data payload; the TCP and IP headers must still be added to the packet, and are assumed to occupy 40 bytes total.

sackOK" denotes acceptance by the client/sender of the "selective acknowledgement" option

The purpose of an ACK is to help track bytes exchanged


http://www.taosecurity.com/intv2-8.html

Richard Stevens - TCP/IP Illustrated, Volume 1: The Protocols

No comments:

Post a Comment