Wireshark-users: [Wireshark-users] Fin directly after SYN/ACK
From: "Linnartz, Pit" <Pit.Linnartz@xxxxxxxxxxx>
Date: Fri, 29 Jun 2007 03:46:01 +0200
Title: Fin directly after SYN/ACK

Hello,

I see the following behaviour on a SUSE Linux 2.6.16.27-0.9-smp kernel. With
the initial SYN having WS=0 the WS=9 in the 2'nd line isn't taken into account.
If so it looks to me that the windowsize of 12 is the reason that the FIN is
directly send. Is this the correct behaviour?

Many thanks in advance
 Pit
No.     Time        Source                Destination           Protocol
Info                                                          
  11112 20.988429   10.100.184.91         10.100.0.98           TCP      53486 35975 [SYN] Seq=1409073086 Len=0 MSS=1460 TSV=101256718 TSER=0 WS=0  

  11113 20.988446   10.100.0.98           10.100.184.91         TCP      35975  53486 [SYN, ACK] Seq=277483755 Ack=1409073087 Win=5792 Len=0 MSS=1460 TSV=227785901 TSER=101256718 WS=9

  11114 20.988803   10.100.184.91         10.100.0.98           TCP      53486  35975 [ACK] Seq=1409073087 Ack=277483756 Win=5840 Len=0 TSV=101256718 TSER=227785901

  11115 20.989047   10.100.0.98           10.100.184.91         TCP      35975  53486 [FIN, ACK] Seq=277483756 Ack=1409073087 Win=12 Len=0 TSV=227785901 TSER=101256718

  11116 20.989303   10.100.184.91         10.100.0.98           TCP      53486  35975 [PSH, ACK] Seq=1409073087 Ack=277483756 Win=5840 Len=285 TSV=101256718 TSER=227785901[Packet size limited during capture]

  11117 20.989319   10.100.0.98           10.100.184.91         TCP      35975  53486 [RST] Seq=277483756 Len=0                        


T-Mobile Deutschland GmbH
Aufsichtsrat: Hamid Akhavan (Vorsitzender)
Geschäftsführung: Philipp Humm (Sprecher), Thomas Berlemann, Stefan Homeister, Holger Kranzusch, Günther Ottendorfer, Dr. Raphael Kübler, Dr. Steffen Roehn
Handelsregister: Amtsgericht Bonn, HRB 59 19
Sitz der Gesellschaft: Bonn
WEEE-Reg.-Nr.: DE60800328