Forum Discussion
Understanding tcpdump output
1) From other links, their tcpdump would display the timestamp but it seems from mine I'm getting the counting of seconds from the time I start the tcpdump. How do I get the F5 timestamp as I will need it for investigation purpose ?
are you using wireshark? if yes, there is time display format under view menu.
2) On line 4, the Seq value changes to "1" does it means data is being push from the source to destination ?
sequence number is 1 because it is the first packet containing payload.
3) On line 5, the Ack value display as "187" does it means it's different connection from the previous one ?
187 is acknowledgement of packet 4.
Understanding TCP Sequence and Acknowledgment Numbers by stretch
http://packetlife.net/blog/2010/jun/7/understanding-tcp-sequence-acknowledgment-numbers/
4) On line 14, the FIN would means a graceful closure of the connection, would I be able to tell which connection is being close ?
i do not see 3 way handshake of that connection (between port 18192 and port 10084).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
