Forum Discussion

dirome's avatar
dirome
Icon for Cirrus rankCirrus
Oct 22, 2014

What is flag SWE

Hi,

 

I have problems with balance of a one application, because after aproximately of 2 minutes the connection falls, on analisys that a did, I am seeing Flag SWE but i dont know what is that, could you say me what is SE?

 

And what could cuase of connection falls?

 

Below tcpdump output:

 

15:16:54.217555 IP 82.250.92.67.54287 > 82.250.92.55.9191: SWE 4092529910:4092529910(0) win 8192 15:16:54.217596 IP 82.250.92.55.9191 > 82.250.92.67.54287: S 3181026550:3181026550(0) ack 4092529911 win 4380 15:16:54.217848 IP 82.250.92.67.54287 > 82.250.92.55.9191: . ack 1 win 64240 15:16:54.219456 IP 82.250.92.67.54288 > 82.250.92.55.9191: SWE 17466884:17466884(0) win 8192 15:16:54.219475 IP 82.250.92.55.9191 > 82.250.92.67.54288: S 3447386030:3447386030(0) ack 17466885 win 4380 15:16:54.219671 IP 82.250.92.67.54288 > 82.250.92.55.9191: . ack 1 win 64240 15:16:54.222925 IP 82.250.92.67.54287 > 82.250.92.55.9191: P 1:382(381) ack 1 win 64240 15:16:54.222937 IP 82.250.92.55.9191 > 82.250.92.67.54287: . ack 382 win 4761 15:16:54.267736 IP 82.250.92.55.9191 > 82.250.92.67.54287: P 1:264(263) ack 382 win 4761 15:16:54.317375 IP 82.250.92.67.54287 > 82.250.92.55.9191: . ack 264 win 63977 15:17:02.623953 IP 82.250.92.67.54289 > 82.250.92.55.8080: SWE 3725054225:3725054225(0) win 8192 15:17:02.624013 IP 82.250.92.55.8080 > 82.250.92.67.54289: S 789412012:789412012(0) ack 3725054226 win 4380 15:17:02.624254 IP 82.250.92.67.54289 > 82.250.92.55.8080: . ack 1 win 64240 15:17:02.628935 IP 82.250.92.67.54289 > 82.250.92.55.8080: P 1:425(424) ack 1 win 64240 15:17:02.628946 IP 82.250.92.55.8080 > 82.250.92.67.54289: . ack 425 win 4804 15:17:02.634785 IP 82.250.92.55.8080 > 82.250.92.67.54289: P 1:1461(1460) ack 425 win 4804 15:17:02.634794 IP 82.250.92.55.8080 > 82.250.92.67.54289: P 1461:2921(1460) ack 425 win 4804 15:17:02.634799 IP 82.250.92.55.8080 > 82.250.92.67.54289: P 2921:4381(1460) ack 425 win 4804 15:17:02.634993 IP 82.250.92.55.8080 > 82.250.92.67.54289: P 4381:4382(1) ack 425 win 4804 15:17:02.635080 IP 82.250.92.67.54289 > 82.250.92.55.8080: . ack 4381 win 64240

 

2 Replies

  • They have to do with explicit congestion notification. From the manpage: W (ECN CWR), E (ECN-Echo)

     

    I am not overly familiar with this, but there seem to be a lot of problems in the past from different routers or firewalls not supporting this and breaking connections. I can't find any references to it that aren't 10+ years old. Since it is in the SYN packet though(the S in SWE), I would expect if this was your problem you wouldn't work at all.

     

  • From my experience, problems with ECN prevent connectivity completely, not break it after 2 minutes. It doesn't sound like this is causing your problem.