Wireshark-users: [Wireshark-users] TCP Window Update
From: Xtrolyte <xtrolyte@xxxxxxxxx>
Date: Wed, 2 Jan 2008 19:43:13 -0600
In doing some analysis with Wireshark, I've been seeing a lot of TCP Window Update packets. I understand the basics of what this means....as in the source and destination changing their TCP receive windows to adjust for the amount of data each can handle. Is this understanding correct? Also, in a normal capture, should I see a lot of these. What is it a sign of when I see a ton of these in a capture?
 
Cheers.