Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- No. Time Source Destination Protocol Length Info
- 1 0.000000 PFSENSE_PUBLIC_IP 172.217.22.78 TCP 74 22019 → 443 [SYN] Seq=0 Win=65228 Len=0 MSS=1460 WS=128 SACK_PERM=1 TSval=14269633 TSecr=0
- Frame 1: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Encapsulation type: Ethernet (1)
- Arrival Time: Mar 28, 2020 18:02:46.187424000 CET
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1585414966.187424000 seconds
- [Time delta from previous captured frame: 0.000000000 seconds]
- [Time delta from previous displayed frame: 0.000000000 seconds]
- [Time since reference or first frame: 0.000000000 seconds]
- Frame Number: 1
- Frame Length: 74 bytes (592 bits)
- Capture Length: 74 bytes (592 bits)
- [Frame is marked: True]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: PFSENSE_MAC (PFSENSE_MAC), Dst: KVM_HOST_MAC (KVM_HOST_MAC)
- Destination: KVM_HOST_MAC (KVM_HOST_MAC)
- Address: KVM_HOST_MAC (KVM_HOST_MAC)
- .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: PFSENSE_MAC (PFSENSE_MAC)
- Address: PFSENSE_MAC (PFSENSE_MAC)
- .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: PFSENSE_PUBLIC_IP, Dst: 172.217.22.78
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 60
- Identification: 0x0000 (0)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- ...0 0000 0000 0000 = Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0xb8cd [validation disabled]
- [Header checksum status: Unverified]
- Source: PFSENSE_PUBLIC_IP
- Destination: 172.217.22.78
- Transmission Control Protocol, Src Port: 22019, Dst Port: 443, Seq: 0, Len: 0
- Source Port: 22019
- Destination Port: 443
- [Stream index: 0]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- [Next sequence number: 0 (relative sequence number)]
- Acknowledgment number: 0
- 1010 .... = Header Length: 40 bytes (10)
- Flags: 0x002 (SYN)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 443]
- [Connection establish request (SYN): server port 443]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ··········S·]
- Window size value: 65228
- [Calculated window size: 65228]
- Checksum: 0x821d [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (20 bytes), Maximum segment size, No-Operation (NOP), Window scale, SACK permitted, Timestamps
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 7 (multiply by 128)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 7
- [Multiplier: 128]
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- TCP Option - Timestamps: TSval 14269633, TSecr 0
- Kind: Time Stamp Option (8)
- Length: 10
- Timestamp value: 14269633
- Timestamp echo reply: 0
- [Timestamps]
- [Time since first frame in this TCP stream: 0.000000000 seconds]
- [Time since previous frame in this TCP stream: 0.000000000 seconds]
- No. Time Source Destination Protocol Length Info
- 36 6.205160 PFSENSE_PUBLIC_IP 172.217.22.78 TCP 74 22379 → 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1 TSval=3863588204 TSecr=0 WS=128
- Frame 36: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Encapsulation type: Ethernet (1)
- Arrival Time: Mar 28, 2020 18:02:52.392584000 CET
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1585414972.392584000 seconds
- [Time delta from previous captured frame: 6.139376000 seconds]
- [Time delta from previous displayed frame: 6.205160000 seconds]
- [Time since reference or first frame: 6.205160000 seconds]
- Frame Number: 36
- Frame Length: 74 bytes (592 bits)
- Capture Length: 74 bytes (592 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: PFSENSE_MAC (PFSENSE_MAC), Dst: KVM_HOST_MAC (KVM_HOST_MAC)
- Destination: KVM_HOST_MAC (KVM_HOST_MAC)
- Address: KVM_HOST_MAC (KVM_HOST_MAC)
- .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: PFSENSE_MAC (PFSENSE_MAC)
- Address: PFSENSE_MAC (PFSENSE_MAC)
- .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: PFSENSE_PUBLIC_IP, Dst: 172.217.22.78
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 60
- Identification: 0x7ce0 (31968)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- ...0 0000 0000 0000 = Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x3ced [validation disabled]
- [Header checksum status: Unverified]
- Source: PFSENSE_PUBLIC_IP
- Destination: 172.217.22.78
- Transmission Control Protocol, Src Port: 22379, Dst Port: 443, Seq: 0, Len: 0
- Source Port: 22379
- Destination Port: 443
- [Stream index: 1]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- [Next sequence number: 0 (relative sequence number)]
- Acknowledgment number: 0
- 1010 .... = Header Length: 40 bytes (10)
- Flags: 0x002 (SYN)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 443]
- [Connection establish request (SYN): server port 443]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ··········S·]
- Window size value: 64240
- [Calculated window size: 64240]
- Checksum: 0x459d [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- TCP Option - Timestamps: TSval 3863588204, TSecr 0
- Kind: Time Stamp Option (8)
- Length: 10
- Timestamp value: 3863588204
- Timestamp echo reply: 0
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 7 (multiply by 128)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 7
- [Multiplier: 128]
- [Timestamps]
- [Time since first frame in this TCP stream: 0.000000000 seconds]
- [Time since previous frame in this TCP stream: 0.000000000 seconds]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement