Wireshark-users: [Wireshark-users] TCP checksum offloading and non-zero checksums
From: Vic Chester <vcsubscriptions@xxxxxxxxx>
Date: Fri, 23 Nov 2018 18:57:42 -0500
I was under the impression that if TCP checksum offloading occurs, the actual TCP checksum would be zero. Can anyone confirm?

The reason I ask is because I have a capture from a Centos 7 VM where several packets (73) are reported as having incorrect TCP checksums. The actual checksums are not zero however, and some of them when have replies to them. If the checksum was really incorrect the ip stack of the receiver should have discarded the packet.

Can anyone confirm or explain this behavior?