Voilà je viens de capturer une autre séquence.
Le MSS est bien comme je l’ai configuré (576) par contre encore des paquest perdus ?
[code]No. Time Source Destination Protocol Length Info New Column
25 833.680189 88.12.46.10 88.190.31.67 TCP 74 46656 > http [SYN] Seq=0 Win=5840 Len=0 MSS=1452 SACK_PERM=1 TSval=1895576 TSecr=0 WS=2 25
Frame 25: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
Arrival Time: Apr 14, 2012 18:17:57.840296000 CEST
Epoch Time: 1334420277.840296000 seconds
[Time delta from previous captured frame: 213.542470000 seconds]
[Time delta from previous displayed frame: 0.000000000 seconds]
[Time since reference or first frame: 833.680189000 seconds]
Frame Number: 25
Frame Length: 74 bytes (592 bits)
Capture Length: 74 bytes (592 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 60
Identification: 0x5f1d (24349)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe787 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 0, Len: 0
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 0 (relative sequence number)
Header length: 40 bytes
Flags: 0x02 (SYN)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …0 … = Acknowledgement: Not set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish request (SYN): server port http]
[Message: Connection establish request (SYN): server port http]
[Severity level: Chat]
[Group: Sequence]
… … …0 = Fin: Not set
Window size value: 5840
[Calculated window size: 5840]
Checksum: 0x022f [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (20 bytes)
Maximum segment size: 1452 bytes
TCP SACK Permitted Option: True
Timestamps: TSval 1895576, TSecr 0
Kind: Timestamp (8)
Length: 10
Timestamp value: 1895576
Timestamp echo reply: 0
No-Operation (NOP)
Window scale: 1 (multiply by 2)
Kind: Window Scale (3)
Length: 3
Shift count: 1
[Multiplier: 2]
No. Time Source Destination Protocol Length Info New Column
26 833.680224 88.190.31.67 88.12.46.10 TCP 74 http > 46656 [SYN, ACK] Seq=0 Ack=1 Win=4992 Len=0 MSS=576 SACK_PERM=1 TSval=1213171761 TSecr=1895576 WS=128 26
Frame 26: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
Arrival Time: Apr 14, 2012 18:17:57.840331000 CEST
Epoch Time: 1334420277.840331000 seconds
[Time delta from previous captured frame: 0.000035000 seconds]
[Time delta from previous displayed frame: 0.000035000 seconds]
[Time since reference or first frame: 833.680224000 seconds]
Frame Number: 26
Frame Length: 74 bytes (592 bits)
Capture Length: 74 bytes (592 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 60
Identification: 0x0000 (0)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x3ca5 [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 0, Ack: 1, Len: 0
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 0 (relative sequence number)
Acknowledgement number: 1 (relative ack number)
Header length: 40 bytes
Flags: 0x12 (SYN, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port http]
[Message: Connection establish acknowledge (SYN+ACK): server port http]
[Severity level: Chat]
[Group: Sequence]
… … …0 = Fin: Not set
Window size value: 4992
[Calculated window size: 4992]
Checksum: 0x7d52 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (20 bytes)
Maximum segment size: 576 bytes
TCP SACK Permitted Option: True
Timestamps: TSval 1213171761, TSecr 1895576
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213171761
Timestamp echo reply: 1895576
No-Operation (NOP)
Window scale: 7 (multiply by 128)
Kind: Window Scale (3)
Length: 3
Shift count: 7
[Multiplier: 128]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 25]
[The RTT to ACK the segment was: 0.000035000 seconds]
No. Time Source Destination Protocol Length Info New Column
27 833.714025 88.12.46.10 88.190.31.67 TCP 66 46656 > http [ACK] Seq=1 Ack=1 Win=5840 Len=0 TSval=1895583 TSecr=1213171761 27
Frame 27: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Arrival Time: Apr 14, 2012 18:17:57.874132000 CEST
Epoch Time: 1334420277.874132000 seconds
[Time delta from previous captured frame: 0.033801000 seconds]
[Time delta from previous displayed frame: 0.033801000 seconds]
[Time since reference or first frame: 833.714025000 seconds]
Frame Number: 27
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x5f1e (24350)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe78e [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 1, Ack: 1, Len: 0
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 1 (relative sequence number)
Acknowledgement number: 1 (relative ack number)
Header length: 32 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 2920
[Calculated window size: 5840]
[Window size scaling factor: 2]
Checksum: 0xb0bb [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1895583, TSecr 1213171761
Kind: Timestamp (8)
Length: 10
Timestamp value: 1895583
Timestamp echo reply: 1213171761
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 26]
[The RTT to ACK the segment was: 0.033801000 seconds]
No. Time Source Destination Protocol Length Info New Column
28 833.752469 88.12.46.10 88.190.31.67 TCP 300 [TCP segment of a reassembled PDU] 28
Frame 28: 300 bytes on wire (2400 bits), 300 bytes captured (2400 bits)
Arrival Time: Apr 14, 2012 18:17:57.912576000 CEST
Epoch Time: 1334420277.912576000 seconds
[Time delta from previous captured frame: 0.038444000 seconds]
[Time delta from previous displayed frame: 0.038444000 seconds]
[Time since reference or first frame: 833.752469000 seconds]
Frame Number: 28
Frame Length: 300 bytes (2400 bits)
Capture Length: 300 bytes (2400 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 286
Identification: 0x5f1f (24351)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe6a3 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 1, Ack: 1, Len: 234
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 1 (relative sequence number)
[Next sequence number: 235 (relative sequence number)]
Acknowledgement number: 1 (relative ack number)
Header length: 32 bytes
Flags: 0x18 (PSH, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 1… = Push: Set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 2920
[Calculated window size: 5840]
[Window size scaling factor: 2]
Checksum: 0x6383 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1895590, TSecr 1213171761
Kind: Timestamp (8)
Length: 10
Timestamp value: 1895590
Timestamp echo reply: 1213171761
[SEQ/ACK analysis]
[Bytes in flight: 234]
TCP segment data (234 bytes)
No. Time Source Destination Protocol Length Info New Column
29 833.752510 88.190.31.67 88.12.46.10 TCP 66 http > 46656 [ACK] Seq=1 Ack=235 Win=6144 Len=0 TSval=1213171779 TSecr=1895590 29
Frame 29: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Arrival Time: Apr 14, 2012 18:17:57.912617000 CEST
Epoch Time: 1334420277.912617000 seconds
[Time delta from previous captured frame: 0.000041000 seconds]
[Time delta from previous displayed frame: 0.000041000 seconds]
[Time since reference or first frame: 833.752510000 seconds]
Frame Number: 29
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0xa811 (43025)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x949b [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 1, Ack: 235, Len: 0
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 1 (relative sequence number)
Acknowledgement number: 235 (relative ack number)
Header length: 32 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 48
[Calculated window size: 6144]
[Window size scaling factor: 128]
Checksum: 0xbaf0 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1213171779, TSecr 1895590
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213171779
Timestamp echo reply: 1895590
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 28]
[The RTT to ACK the segment was: 0.000041000 seconds]
No. Time Source Destination Protocol Length Info New Column
30 833.759279 88.12.46.10 88.190.31.67 TCP 438 [TCP Previous segment lost] [TCP segment of a reassembled PDU] 30
Frame 30: 438 bytes on wire (3504 bits), 438 bytes captured (3504 bits)
Arrival Time: Apr 14, 2012 18:17:57.919386000 CEST
Epoch Time: 1334420277.919386000 seconds
[Time delta from previous captured frame: 0.006769000 seconds]
[Time delta from previous displayed frame: 0.006769000 seconds]
[Time since reference or first frame: 833.759279000 seconds]
Frame Number: 30
Frame Length: 438 bytes (3504 bits)
Capture Length: 438 bytes (3504 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 424
Identification: 0x5f21 (24353)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe617 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 1675, Ack: 1, Len: 372
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 1675 (relative sequence number)
[Next sequence number: 2047 (relative sequence number)]
Acknowledgement number: 1 (relative ack number)
Header length: 32 bytes
Flags: 0x18 (PSH, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 1… = Push: Set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 2920
[Calculated window size: 5840]
[Window size scaling factor: 2]
Checksum: 0x2b1e [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1895590, TSecr 1213171761
Kind: Timestamp (8)
Length: 10
Timestamp value: 1895590
Timestamp echo reply: 1213171761
[SEQ/ACK analysis]
[TCP Analysis Flags]
[A segment before this frame was lost]
[Expert Info (Warn/Sequence): Previous segment lost (common at capture start)]
[Message: Previous segment lost (common at capture start)]
[Severity level: Warn]
[Group: Sequence]
TCP segment data (372 bytes)
No. Time Source Destination Protocol Length Info New Column
31 833.759310 88.190.31.67 88.12.46.10 TCP 78 [TCP Dup ACK 29#1] http > 46656 [ACK] Seq=1 Ack=235 Win=6144 Len=0 TSval=1213171781 TSecr=1895590 SLE=1675 SRE=2047 31
Frame 31: 78 bytes on wire (624 bits), 78 bytes captured (624 bits)
Arrival Time: Apr 14, 2012 18:17:57.919417000 CEST
Epoch Time: 1334420277.919417000 seconds
[Time delta from previous captured frame: 0.000031000 seconds]
[Time delta from previous displayed frame: 0.000031000 seconds]
[Time since reference or first frame: 833.759310000 seconds]
Frame Number: 31
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0xa812 (43026)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x948e [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 1, Ack: 235, Len: 0
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 1 (relative sequence number)
Acknowledgement number: 235 (relative ack number)
Header length: 44 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 48
[Calculated window size: 6144]
[Window size scaling factor: 128]
Checksum: 0x5ae8 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1213171781, TSecr 1895590
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213171781
Timestamp echo reply: 1895590
No-Operation (NOP)
No-Operation (NOP)
SACK: 1675-2047
left edge = 1675 (relative)
right edge = 2047 (relative)
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 29]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence]
No. Time Source Destination Protocol Length Info New Column
32 853.997445 88.190.31.67 88.12.46.10 HTTP 404 HTTP/1.1 408 Request Timeout 32
Frame 32: 404 bytes on wire (3232 bits), 404 bytes captured (3232 bits)
Arrival Time: Apr 14, 2012 18:18:18.157552000 CEST
Epoch Time: 1334420298.157552000 seconds
[Time delta from previous captured frame: 20.238135000 seconds]
[Time delta from previous displayed frame: 20.238135000 seconds]
[Time since reference or first frame: 853.997445000 seconds]
Frame Number: 32
Frame Length: 404 bytes (3232 bits)
Capture Length: 404 bytes (3232 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:http:data]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 390
Identification: 0xa813 (43027)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x9347 [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 1, Ack: 235, Len: 326
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 1 (relative sequence number)
[Next sequence number: 327 (relative sequence number)]
Acknowledgement number: 235 (relative ack number)
Header length: 44 bytes
Flags: 0x18 (PSH, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 1… = Push: Set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 48
[Calculated window size: 6144]
[Window size scaling factor: 128]
Checksum: 0xff8f [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1213176840, TSecr 1895590
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213176840
Timestamp echo reply: 1895590
No-Operation (NOP)
No-Operation (NOP)
SACK: 1675-2047
left edge = 1675 (relative)
right edge = 2047 (relative)
[SEQ/ACK analysis]
[Bytes in flight: 326]
Hypertext Transfer Protocol
HTTP/1.1 408 Request Timeout\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 408 Request Timeout\r\n]
[Message: HTTP/1.1 408 Request Timeout\r\n]
[Severity level: Chat]
[Group: Sequence]
Request Version: HTTP/1.1
Status Code: 408
Response Phrase: Request Timeout
Date: Sat, 14 Apr 2012 16:17:57 GMT\r\n
Server: Apache/2.2.16 (Debian)\r\n
X-Powered-By: PHP/5.3.3-7+squeeze8\r\n
Set-Cookie: PHPSESSID=gl7512acak07o1037ecrvo4lp2; path=/\r\n
Vary: Accept-Encoding\r\n
Content-Encoding: gzip\r\n
Content-Length: 20\r\n
[Content length: 20]
Connection: close\r\n
Content-Type: text/html\r\n
\r\n
Content-encoded entity body (gzip): 20 bytes [Error: Decompression failed]
Data (20 bytes)
0000 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 …
0010 00 00 00 00 …
Data: 1f8b080000000000000303000000000000000000
[Length: 20]
No. Time Source Destination Protocol Length Info New Column
33 853.997500 88.190.31.67 88.12.46.10 TCP 78 http > 46656 [FIN, ACK] Seq=327 Ack=235 Win=6144 Len=0 TSval=1213176840 TSecr=1895590 SLE=1675 SRE=2047 33
Frame 33: 78 bytes on wire (624 bits), 78 bytes captured (624 bits)
Arrival Time: Apr 14, 2012 18:18:18.157607000 CEST
Epoch Time: 1334420298.157607000 seconds
[Time delta from previous captured frame: 0.000055000 seconds]
[Time delta from previous displayed frame: 0.000055000 seconds]
[Time since reference or first frame: 853.997500000 seconds]
Frame Number: 33
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0xa814 (43028)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x948c [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 327, Ack: 235, Len: 0
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 327 (relative sequence number)
Acknowledgement number: 235 (relative ack number)
Header length: 44 bytes
Flags: 0x11 (FIN, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 48
[Calculated window size: 6144]
[Window size scaling factor: 128]
Checksum: 0x45de [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1213176840, TSecr 1895590
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213176840
Timestamp echo reply: 1895590
No-Operation (NOP)
No-Operation (NOP)
SACK: 1675-2047
left edge = 1675 (relative)
right edge = 2047 (relative)
No. Time Source Destination Protocol Length Info New Column
34 854.043875 88.12.46.10 88.190.31.67 TCP 66 46656 > http [ACK] Seq=2047 Ack=327 Win=6912 Len=0 TSval=1899648 TSecr=1213176840 34
Frame 34: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Arrival Time: Apr 14, 2012 18:18:18.203982000 CEST
Epoch Time: 1334420298.203982000 seconds
[Time delta from previous captured frame: 0.046375000 seconds]
[Time delta from previous displayed frame: 0.046375000 seconds]
[Time since reference or first frame: 854.043875000 seconds]
Frame Number: 34
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x5f28 (24360)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe784 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 2047, Ack: 327, Len: 0
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 2047 (relative sequence number)
Acknowledgement number: 327 (relative ack number)
Header length: 32 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 3456
[Calculated window size: 6912]
[Window size scaling factor: 2]
Checksum: 0x81a7 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1899648, TSecr 1213176840
Kind: Timestamp (8)
Length: 10
Timestamp value: 1899648
Timestamp echo reply: 1213176840
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 32]
[The RTT to ACK the segment was: 0.046430000 seconds]
No. Time Source Destination Protocol Length Info New Column
35 854.084740 88.12.46.10 88.190.31.67 TCP 66 46656 > http [ACK] Seq=2047 Ack=328 Win=6912 Len=0 TSval=1899657 TSecr=1213176840 35
Frame 35: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Arrival Time: Apr 14, 2012 18:18:18.244847000 CEST
Epoch Time: 1334420298.244847000 seconds
[Time delta from previous captured frame: 0.040865000 seconds]
[Time delta from previous displayed frame: 0.040865000 seconds]
[Time since reference or first frame: 854.084740000 seconds]
Frame Number: 35
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x5f29 (24361)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe783 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 2047, Ack: 328, Len: 0
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 2047 (relative sequence number)
Acknowledgement number: 328 (relative ack number)
Header length: 32 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 3456
[Calculated window size: 6912]
[Window size scaling factor: 2]
Checksum: 0x819d [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1899657, TSecr 1213176840
Kind: Timestamp (8)
Length: 10
Timestamp value: 1899657
Timestamp echo reply: 1213176840
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 33]
[The RTT to ACK the segment was: 0.087240000 seconds]
No. Time Source Destination Protocol Length Info New Column
36 854.099020 88.12.46.10 88.190.31.67 TCP 66 46656 > http [FIN, ACK] Seq=2047 Ack=328 Win=6912 Len=0 TSval=1899659 TSecr=1213176840 36
Frame 36: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
Arrival Time: Apr 14, 2012 18:18:18.259127000 CEST
Epoch Time: 1334420298.259127000 seconds
[Time delta from previous captured frame: 0.014280000 seconds]
[Time delta from previous displayed frame: 0.014280000 seconds]
[Time since reference or first frame: 854.099020000 seconds]
Frame Number: 36
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: HTTP]
[Coloring Rule String: http || tcp.port == 80]
Ethernet II, Src: Cisco_f6:94:7f (00:25:45:f6:94:7f), Dst: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Destination: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.12.46.10 (88.12.46.10), Dst: 88.190.31.67 (88.190.31.67)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x5f2a (24362)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 54
Protocol: TCP (6)
Header checksum: 0xe782 [correct]
[Good: True]
[Bad: False]
Source: 88.12.46.10 (88.12.46.10)
Destination: 88.190.31.67 (88.190.31.67)
Transmission Control Protocol, Src Port: 46656 (46656), Dst Port: http (80), Seq: 2047, Ack: 328, Len: 0
Source port: 46656 (46656)
Destination port: http (80)
[Stream index: 3]
Sequence number: 2047 (relative sequence number)
Acknowledgement number: 328 (relative ack number)
Header length: 32 bytes
Flags: 0x11 (FIN, ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 3456
[Calculated window size: 6912]
[Window size scaling factor: 2]
Checksum: 0x819a [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1899659, TSecr 1213176840
Kind: Timestamp (8)
Length: 10
Timestamp value: 1899659
Timestamp echo reply: 1213176840
No. Time Source Destination Protocol Length Info New Column
37 854.099041 88.190.31.67 88.12.46.10 TCP 78 [TCP Dup ACK 33#1] http > 46656 [ACK] Seq=328 Ack=235 Win=6144 Len=0 TSval=1213176866 TSecr=1895590 SLE=1675 SRE=2048 37
Frame 37: 78 bytes on wire (624 bits), 78 bytes captured (624 bits)
Arrival Time: Apr 14, 2012 18:18:18.259148000 CEST
Epoch Time: 1334420298.259148000 seconds
[Time delta from previous captured frame: 0.000021000 seconds]
[Time delta from previous displayed frame: 0.000021000 seconds]
[Time since reference or first frame: 854.099041000 seconds]
Frame Number: 37
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags]
Ethernet II, Src: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff), Dst: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Destination: Cisco_f6:94:7f (00:25:45:f6:94:7f)
Address: Cisco_f6:94:7f (00:25:45:f6:94:7f)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Source: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
Address: Dell_e4:4a:ff (bc:30:5b:e4:4a:ff)
… …0 … … … … = IG bit: Individual address (unicast)
… …0. … … … … = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 88.190.31.67 (88.190.31.67), Dst: 88.12.46.10 (88.12.46.10)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00… = Differentiated Services Codepoint: Default (0x00)
… …00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0xa815 (43029)
Flags: 0x02 (Don’t Fragment)
0… … = Reserved bit: Not set
.1… … = Don’t fragment: Set
…0. … = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x948b [correct]
[Good: True]
[Bad: False]
Source: 88.190.31.67 (88.190.31.67)
Destination: 88.12.46.10 (88.12.46.10)
Transmission Control Protocol, Src Port: http (80), Dst Port: 46656 (46656), Seq: 328, Ack: 235, Len: 0
Source port: http (80)
Destination port: 46656 (46656)
[Stream index: 3]
Sequence number: 328 (relative sequence number)
Acknowledgement number: 235 (relative ack number)
Header length: 44 bytes
Flags: 0x10 (ACK)
000. … … = Reserved: Not set
…0 … … = Nonce: Not set
… 0… … = Congestion Window Reduced (CWR): Not set
… .0… … = ECN-Echo: Not set
… …0. … = Urgent: Not set
… …1 … = Acknowledgement: Set
… … 0… = Push: Not set
… … .0… = Reset: Not set
… … …0. = Syn: Not set
… … …0 = Fin: Not set
Window size value: 48
[Calculated window size: 6144]
[Window size scaling factor: 128]
Checksum: 0x45c3 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes)
No-Operation (NOP)
No-Operation (NOP)
Timestamps: TSval 1213176866, TSecr 1895590
Kind: Timestamp (8)
Length: 10
Timestamp value: 1213176866
Timestamp echo reply: 1895590
No-Operation (NOP)
No-Operation (NOP)
SACK: 1675-2048
left edge = 1675 (relative)
right edge = 2048 (relative)
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 33]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence][/code]