Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Frame 149: 590 bytes on wire (4720 bits), 590 bytes captured (4720 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 108.177.112.136
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0xc0 (DSCP: CS6, ECN: Not-ECT)
- 1100 00.. = Differentiated Services Codepoint: Class Selector 6 (48)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 576
- Identification: 0x4295 (17045)
- Flags: 0x00
- 0... .... = Reserved bit: Not set
- .0.. .... = Don't fragment: Not set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 64
- Protocol: ICMP (1)
- Header checksum: 0x4e2d [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.0.0.2
- Destination: 108.177.112.136
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP Country: United States]
- [Destination GeoIP AS Number: AS15169 Google Inc.]
- [Destination GeoIP City: Mountain View, CA]
- [Destination GeoIP Latitude: 37.419201]
- [Destination GeoIP Longitude: -122.057404]
- Internet Control Message Protocol
- Type: 3 (Destination unreachable)
- Code: 4 (Fragmentation needed)
- Checksum: 0x4295 [correct]
- [Checksum Status: Good]
- Unused: 0000
- MTU of next hop: 1390
- Internet Protocol Version 4, Src: 108.177.112.136, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 1400
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x4f45 [validation disabled]
- [Header checksum status: Unverified]
- Source: 108.177.112.136
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 46230, Seq: 2905003006, Ack: 1909895621
- Source Port: 443
- Destination Port: 46230
- Sequence number: 2905003006
- [Stream index: 13]
- Sequence number: 2905003006 (relative sequence number)
- Acknowledgment number: 1909895621 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x010 (ACK)
- Window size value: 115
- [Calculated window size: 115]
- [Window size scaling factor: 256]
- Checksum: 0x73da [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- No-Operation (NOP)
- Timestamps: TSval 751336620, TSecr 74445
- Secure Sockets Layer
- Ignored Unknown Record
- [Expert Info (Warning/Protocol): Ignored Unknown Record]
- [Ignored Unknown Record]
- [Severity level: Warning]
- [Group: Protocol]
- Frame 159: 590 bytes on wire (4720 bits), 590 bytes captured (4720 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 108.177.112.136
- Internet Control Message Protocol
- Type: 3 (Destination unreachable)
- Code: 4 (Fragmentation needed)
- Checksum: 0xe3b1 [correct]
- [Checksum Status: Good]
- Unused: 0000
- MTU of next hop: 1390
- Internet Protocol Version 4, Src: 108.177.112.136, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 1400
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x4f45 [validation disabled]
- [Header checksum status: Unverified]
- Source: 108.177.112.136
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Source GeoIP Country: United States]
- [Source GeoIP AS Number: AS15169 Google Inc.]
- [Source GeoIP City: Mountain View, CA]
- [Source GeoIP Latitude: 37.419201]
- [Source GeoIP Longitude: -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 46230, Seq: 2905001658, Ack: 1909895621
- Source Port: 443
- Destination Port: 46230
- Sequence number: 2905001658
- [Stream index: 13]
- Sequence number: 2905001658 (relative sequence number)
- Acknowledgment number: 1909895621 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x010 (ACK)
- Window size value: 115
- [Calculated window size: 115]
- [Window size scaling factor: 256]
- Checksum: 0x8071 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- No-Operation (NOP)
- Timestamps: TSval 751337061, TSecr 74540
- Secure Sockets Layer
- TLSv1.2 Record Layer: Handshake Protocol: Server Hello
- Content Type: Handshake (22)
- Version: TLS 1.2 (0x0303)
- Length: 72
- Handshake Protocol: Server Hello
- Frame 160: 1414 bytes on wire (11312 bits), 1414 bytes captured (11312 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 108.177.112.136, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 1400
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x4e45 [validation disabled]
- [Header checksum status: Unverified]
- Source: 108.177.112.136
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Source GeoIP Country: United States]
- [Source GeoIP AS Number: AS15169 Google Inc.]
- [Source GeoIP City: Mountain View, CA]
- [Source GeoIP Latitude: 37.419201]
- [Source GeoIP Longitude: -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 46230, Seq: 1349, Ack: 205, Len: 1348
- Source Port: 443
- Destination Port: 46230
- [Stream index: 13]
- [TCP Segment Len: 1348]
- Sequence number: 1349 (relative sequence number)
- [Next sequence number: 2697 (relative sequence number)]
- Acknowledgment number: 205 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x010 (ACK)
- Window size value: 115
- [Calculated window size: 29440]
- [Window size scaling factor: 256]
- Checksum: 0x71b6 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- No-Operation (NOP)
- Timestamps: TSval 751337073, TSecr 74540
- [SEQ/ACK analysis]
- [iRTT: 0.359988000 seconds]
- [Bytes in flight: 3284]
- [Bytes sent since last PSH flag: 2696]
- [TCP Analysis Flags]
- [Expert Info (Note/Sequence): This frame is a (suspected) retransmission]
- [This frame is a (suspected) retransmission]
- [Severity level: Note]
- [Group: Sequence]
- [The RTO for this segment was: 0.440629000 seconds]
- [RTO based on delta from frame: 150]
- Retransmitted TCP segment data (1348 bytes)
- Frame 405: 312 bytes on wire (2496 bits), 312 bytes captured (2496 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 169.254.169.254
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 298
- Identification: 0x96f0 (38640)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x44df [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.0.0.2
- Destination: 169.254.169.254
- [Source GeoIP: Unknown]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 38082, Dst Port: 80, Seq: 1, Ack: 1, Len: 258
- Source Port: 38082
- Destination Port: 80
- [Stream index: 21]
- [TCP Segment Len: 258]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 259 (relative sequence number)]
- Acknowledgment number: 1 (relative ack number)
- Header Length: 20 bytes
- Flags: 0x018 (PSH, ACK)
- Window size value: 28400
- [Calculated window size: 28400]
- [Window size scaling factor: -2 (no window scaling used)]
- Checksum: 0x5f1b [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- [SEQ/ACK analysis]
- [iRTT: 0.000325000 seconds]
- [Bytes in flight: 258]
- [Bytes sent since last PSH flag: 258]
- Hypertext Transfer Protocol
- GET /computeMetadata/v1/?timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True HTTP/1.1\r\n
- [Expert Info (Chat/Sequence): GET /computeMetadata/v1/?timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True HTTP/1.1\r\n]
- [GET /computeMetadata/v1/?timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True HTTP/1.1\r\n]
- [Severity level: Chat]
- [Group: Sequence]
- Request Method: GET
- Request URI: /computeMetadata/v1/?timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True
- Request URI Path: /computeMetadata/v1/
- Request URI Query: timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True
- Request URI Query Parameter: timeout_sec=89
- Request URI Query Parameter: last_etag=d9d7ea9ecebafaf7
- Request URI Query Parameter: alt=json
- Request URI Query Parameter: recursive=True
- Request URI Query Parameter: wait_for_change=True
- Request Version: HTTP/1.1
- Accept-Encoding: identity\r\n
- Host: metadata.google.internal\r\n
- Metadata-Flavor: Google\r\n
- Connection: close\r\n
- User-Agent: Python-urllib/2.7\r\n
- \r\n
- [Full request URI: http://metadata.google.internal/computeMetadata/v1/?timeout_sec=89&last_etag=d9d7ea9ecebafaf7&alt=json&recursive=True&wait_for_change=True]
- [HTTP request 1/1]
- [Response in frame: 1087]
- Frame 420: 637 bytes on wire (5096 bits), 637 bytes captured (5096 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 169.254.169.254, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 623
- Identification: 0x0000 (0)
- Flags: 0x00
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x1a8b [validation disabled]
- [Header checksum status: Unverified]
- Source: 169.254.169.254
- Destination: 10.0.0.2
- [Source GeoIP: Unknown]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 80, Dst Port: 38076, Seq: 1, Ack: 287, Len: 583
- Source Port: 80
- Destination Port: 38076
- [Stream index: 6]
- [TCP Segment Len: 583]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 584 (relative sequence number)]
- Acknowledgment number: 287 (relative ack number)
- Header Length: 20 bytes
- Flags: 0x018 (PSH, ACK)
- Window size value: 65535
- [Calculated window size: 65535]
- [Window size scaling factor: -2 (no window scaling used)]
- Checksum: 0xbf2b [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- [SEQ/ACK analysis]
- [iRTT: 0.000330000 seconds]
- [Bytes in flight: 583]
- [Bytes sent since last PSH flag: 583]
- Hypertext Transfer Protocol
- HTTP/1.1 200 OK\r\n
- [Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
- [HTTP/1.1 200 OK\r\n]
- [Severity level: Chat]
- [Group: Sequence]
- Request Version: HTTP/1.1
- Status Code: 200
- Response Phrase: OK
- Metadata-Flavor: Google\r\n
- Content-Type: application/json\r\n
- ETag: 31109d51c4b4df85\r\n
- Date: Tue, 17 Jul 2018 22:20:15 GMT\r\n
- Server: Metadata Server for VM\r\n
- Connection: Close\r\n
- Content-Length: 312\r\n
- [Content length: 312]
- X-XSS-Protection: 1; mode=block\r\n
- X-Frame-Options: SAMEORIGIN\r\n
- \r\n
- [HTTP response 1/1]
- [Time since request: 82.019145000 seconds]
- [Request in frame: 70]
- File Data: 312 bytes
- JavaScript Object Notation: application/json
- Array
- Object
- Member Key: accessConfigs
- Array
- Object
- Member Key: externalIp
- String value: 35.188.78.199
- Key: externalIp
- Member Key: type
- String value: ONE_TO_ONE_NAT
- Key: type
- Key: accessConfigs
- Member Key: dnsServers
- Array
- String value: 169.254.169.254
- Key: dnsServers
- Member Key: forwardedIps
- Array
- Key: forwardedIps
- Member Key: gateway
- String value: 10.0.0.1
- Key: gateway
- Member Key: ip
- String value: 10.0.0.2
- Key: ip
- Member Key: ipAliases
- Array
- Key: ipAliases
- Member Key: mac
- String value: 42:01:0a:00:00:02
- Key: mac
- Member Key: network
- String value: projects/338703512437/networks/vpn-network
- Key: network
- Member Key: subnetmask
- String value: 255.255.255.0
- Key: subnetmask
- Member Key: targetInstanceIps
- Array
- Key: targetInstanceIps
- Frame 432: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 172.31.0.1, Dst: 8.8.4.4
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 60
- Identification: 0x06aa (1706)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: UDP (17)
- Header checksum: 0x7bdb [validation disabled]
- [Header checksum status: Unverified]
- Source: 172.31.0.1
- Destination: 8.8.4.4
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., 37.750999, -97.821999]
- User Datagram Protocol, Src Port: 54238, Dst Port: 53
- Source Port: 54238
- Destination Port: 53
- Length: 40
- Checksum: 0xf247 [unverified]
- [Checksum Status: Unverified]
- [Stream index: 17]
- Domain Name System (query)
- Transaction ID: 0xf26e
- Flags: 0x0100 Standard query
- Questions: 1
- Answer RRs: 0
- Authority RRs: 0
- Additional RRs: 0
- Queries
- www.google.com: type A, class IN
- Name: www.google.com
- [Name Length: 14]
- [Label Count: 3]
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Frame 434: 170 bytes on wire (1360 bits), 170 bytes captured (1360 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 8.8.4.4, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 156
- Identification: 0xbe91 (48785)
- Flags: 0x00
- Fragment offset: 0
- Time to live: 52
- Protocol: UDP (17)
- Header checksum: 0xb1b2 [validation disabled]
- [Header checksum status: Unverified]
- Source: 8.8.4.4
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., 37.750999, -97.821999]
- [Destination GeoIP: Unknown]
- User Datagram Protocol, Src Port: 53, Dst Port: 54238
- Source Port: 53
- Destination Port: 54238
- Length: 136
- Checksum: 0xe5e8 [unverified]
- [Checksum Status: Unverified]
- [Stream index: 18]
- Domain Name System (response)
- [Request In: 433]
- [Time: 0.002003000 seconds]
- Transaction ID: 0xf26e
- Flags: 0x8180 Standard query response, No error
- Questions: 1
- Answer RRs: 6
- Authority RRs: 0
- Additional RRs: 0
- Queries
- www.google.com: type A, class IN
- Name: www.google.com
- [Name Length: 14]
- [Label Count: 3]
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Answers
- www.google.com: type A, class IN, addr 74.125.124.105
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.105
- www.google.com: type A, class IN, addr 74.125.124.99
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.99
- www.google.com: type A, class IN, addr 74.125.124.103
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.103
- www.google.com: type A, class IN, addr 74.125.124.104
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.104
- www.google.com: type A, class IN, addr 74.125.124.106
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.106
- www.google.com: type A, class IN, addr 74.125.124.147
- Name: www.google.com
- Type: A (Host Address) (1)
- Class: IN (0x0001)
- Time to live: 138
- Data length: 4
- Address: 74.125.124.147
- Frame 452: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 172.31.0.1, Dst: 74.125.124.105
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 60
- Identification: 0x2f34 (12084)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x9881 [validation disabled]
- [Header checksum status: Unverified]
- Source: 172.31.0.1
- Destination: 74.125.124.105
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- Transmission Control Protocol, Src Port: 39190, Dst Port: 443, Seq: 0, Len: 0
- Source Port: 39190
- Destination Port: 443
- [Stream index: 23]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Acknowledgment number: 0
- Header Length: 40 bytes
- Flags: 0x002 (SYN)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 443]
- [Connection establish request (SYN): server port 443]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ··········S·]
- Window size value: 29200
- [Calculated window size: 29200]
- Checksum: 0xc539 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale
- Maximum segment size: 1460 bytes
- TCP SACK Permitted Option: True
- Timestamps: TSval 82386, TSecr 0
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Window scale: 7 (multiply by 128)
- Frame 453: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 74.125.124.105
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 60
- Identification: 0x2f34 (12084)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x3ba0 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.0.0.2
- Destination: 74.125.124.105
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- Transmission Control Protocol, Src Port: 39190, Dst Port: 443, Seq: 0, Len: 0
- Source Port: 39190
- Destination Port: 443
- [Stream index: 24]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Acknowledgment number: 0
- Header Length: 40 bytes
- Flags: 0x002 (SYN)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 443]
- [Connection establish request (SYN): server port 443]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ··········S·]
- Window size value: 29200
- [Calculated window size: 29200]
- Checksum: 0x67bc [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale
- Maximum segment size: 1360 bytes
- TCP SACK Permitted Option: True
- Timestamps: TSval 82386, TSecr 0
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Window scale: 7 (multiply by 128)
- Frame 454: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 74.125.124.105, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 60
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x69d4 [validation disabled]
- [Header checksum status: Unverified]
- Source: 74.125.124.105
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 39190, Seq: 0, Ack: 1, Len: 0
- Source Port: 443
- Destination Port: 39190
- [Stream index: 24]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Acknowledgment number: 1 (relative ack number)
- Header Length: 40 bytes
- Flags: 0x012 (SYN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port 443]
- [Connection establish acknowledge (SYN+ACK): server port 443]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A··S·]
- Window size value: 28160
- [Calculated window size: 28160]
- Checksum: 0xa802 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale
- Maximum segment size: 1420 bytes
- TCP SACK Permitted Option: True
- Timestamps: TSval 791361978, TSecr 82386
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Window scale: 8 (multiply by 256)
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 453]
- [The RTT to ACK the segment was: 0.000854000 seconds]
- [iRTT: 0.000009000 seconds]
- Frame 466: 261 bytes on wire (2088 bits), 261 bytes captured (2088 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 74.125.124.105
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 247
- Identification: 0x2f37 (12087)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x3ae2 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.0.0.2
- Destination: 74.125.124.105
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- Transmission Control Protocol, Src Port: 39190, Dst Port: 443, Seq: 1, Ack: 1, Len: 195
- Source Port: 39190
- Destination Port: 443
- [Stream index: 24]
- [TCP Segment Len: 195]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 196 (relative sequence number)]
- Acknowledgment number: 1 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x018 (PSH, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 1... = Push: Set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······AP···]
- Window size value: 229
- [Calculated window size: 29312]
- [Window size scaling factor: 128]
- Checksum: 0x134d [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Timestamps: TSval 82726, TSecr 791361978
- [SEQ/ACK analysis]
- [iRTT: 0.000009000 seconds]
- [Bytes in flight: 196]
- [Bytes sent since last PSH flag: 195]
- Secure Sockets Layer
- TLSv1.2 Record Layer: Handshake Protocol: Client Hello
- Content Type: Handshake (22)
- Version: TLS 1.0 (0x0301)
- Length: 190
- Handshake Protocol: Client Hello
- Frame 471: 1414 bytes on wire (11312 bits), 1414 bytes captured (11312 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 74.125.124.105, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 1400
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x6498 [validation disabled]
- [Header checksum status: Unverified]
- Source: 74.125.124.105
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 39190, Seq: 1, Ack: 196, Len: 1348
- Source Port: 443
- Destination Port: 39190
- [Stream index: 24]
- [TCP Segment Len: 1348]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 1349 (relative sequence number)]
- Acknowledgment number: 196 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x010 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A····]
- Window size value: 115
- [Calculated window size: 29440]
- [Window size scaling factor: 256]
- Checksum: 0xf736 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Timestamps: TSval 791362643, TSecr 82726
- [SEQ/ACK analysis]
- [iRTT: 0.000009000 seconds]
- [Bytes in flight: 1349]
- [Bytes sent since last PSH flag: 1348]
- TCP segment data (1271 bytes)
- Secure Sockets Layer
- TLSv1.2 Record Layer: Handshake Protocol: Server Hello
- Content Type: Handshake (22)
- Version: TLS 1.2 (0x0303)
- Length: 72
- Handshake Protocol: Server Hello
- Frame 472: 590 bytes on wire (4720 bits), 590 bytes captured (4720 bits)
- Ethernet II, Src: 42:01:0a:00:00:02 (42:01:0a:00:00:02), Dst: 42:01:0a:00:00:01 (42:01:0a:00:00:01)
- Internet Protocol Version 4, Src: 10.0.0.2, Dst: 74.125.124.105
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0xc0 (DSCP: CS6, ECN: Not-ECT)
- Total Length: 576
- Identification: 0xc2f5 (49909)
- Flags: 0x00
- Fragment offset: 0
- Time to live: 64
- Protocol: ICMP (1)
- Header checksum: 0xe41f [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.0.0.2
- Destination: 74.125.124.105
- [Source GeoIP: Unknown]
- [Destination GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- Internet Control Message Protocol
- Type: 3 (Destination unreachable)
- Code: 4 (Fragmentation needed)
- Checksum: 0x66da [correct]
- [Checksum Status: Good]
- Unused: 0000
- MTU of next hop: 1390
- Internet Protocol Version 4, Src: 74.125.124.105, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 1400
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 63
- Protocol: TCP (6)
- Header checksum: 0x6598 [validation disabled]
- [Header checksum status: Unverified]
- Source: 74.125.124.105
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 39190, Seq: 889595281, Ack: 1378119594
- Source Port: 443
- Destination Port: 39190
- Sequence number: 889595281
- [Stream index: 24]
- Sequence number: 889595281 (relative sequence number)
- Acknowledgment number: 1378119594 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x010 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A····]
- Window size value: 115
- [Calculated window size: 115]
- [Window size scaling factor: 256]
- Checksum: 0xf736 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Timestamps: TSval 791362643, TSecr 82726
- Secure Sockets Layer
- TLSv1.2 Record Layer: Handshake Protocol: Server Hello
- Content Type: Handshake (22)
- Version: TLS 1.2 (0x0303)
- Length: 72
- Handshake Protocol: Server Hello
- Frame 473: 1033 bytes on wire (8264 bits), 1033 bytes captured (8264 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 74.125.124.105, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 1019
- Identification: 0x0000 (0)
- Flags: 0x02 (Don't Fragment)
- Fragment offset: 0
- Time to live: 64
- Protocol: TCP (6)
- Header checksum: 0x6615 [validation disabled]
- [Header checksum status: Unverified]
- Source: 74.125.124.105
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., Mountain View, CA, 37.419201, -122.057404]
- [Destination GeoIP: Unknown]
- Transmission Control Protocol, Src Port: 443, Dst Port: 39190, Seq: 1349, Ack: 196, Len: 967
- Source Port: 443
- Destination Port: 39190
- [Stream index: 24]
- [TCP Segment Len: 967]
- Sequence number: 1349 (relative sequence number)
- [Next sequence number: 2316 (relative sequence number)]
- Acknowledgment number: 196 (relative ack number)
- Header Length: 32 bytes
- Flags: 0x018 (PSH, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 1... = Push: Set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······AP···]
- Window size value: 115
- [Calculated window size: 29440]
- [Window size scaling factor: 256]
- Checksum: 0x19b1 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- No-Operation (NOP)
- Type: 1
- 0... .... = Copy on fragmentation: No
- .00. .... = Class: Control (0)
- ...0 0001 = Number: No-Operation (NOP) (1)
- Timestamps: TSval 791362665, TSecr 82726
- [SEQ/ACK analysis]
- [iRTT: 0.000009000 seconds]
- [Bytes in flight: 2316]
- [Bytes sent since last PSH flag: 2315]
- TCP segment data (967 bytes)
- Secure Sockets Layer
- TLSv1.2 Record Layer: Handshake Protocol: Server Key Exchange
- Content Type: Handshake (22)
- Version: TLS 1.2 (0x0303)
- Length: 115
- Handshake Protocol: Server Key Exchange
- TLSv1.2 Record Layer: Handshake Protocol: Server Hello Done
- Content Type: Handshake (22)
- Version: TLS 1.2 (0x0303)
- Length: 4
- Handshake Protocol: Server Hello Done
- Frame 534: 124 bytes on wire (992 bits), 124 bytes captured (992 bits)
- Ethernet II, Src: 42:01:0a:00:00:01 (42:01:0a:00:00:01), Dst: 42:01:0a:00:00:02 (42:01:0a:00:00:02)
- Internet Protocol Version 4, Src: 8.8.4.4, Dst: 10.0.0.2
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- Total Length: 110
- Identification: 0xa54b (42315)
- Flags: 0x00
- Fragment offset: 0
- Time to live: 51
- Protocol: UDP (17)
- Header checksum: 0xcc26 [validation disabled]
- [Header checksum status: Unverified]
- Source: 8.8.4.4
- Destination: 10.0.0.2
- [Source GeoIP: United States, AS15169 Google Inc., 37.750999, -97.821999]
- [Destination GeoIP: Unknown]
- User Datagram Protocol, Src Port: 53, Dst Port: 44864
- Source Port: 53
- Destination Port: 44864
- Length: 90
- Checksum: 0xb773 [unverified]
- [Checksum Status: Unverified]
- [Stream index: 26]
- Domain Name System (response)
- [Request In: 533]
- [Time: 0.003377000 seconds]
- Transaction ID: 0xf690
- Flags: 0x8180 Standard query response, No error
- Questions: 1
- Answer RRs: 2
- Authority RRs: 0
- Additional RRs: 0
- Queries
- apis.google.com: type AAAA, class IN
- Name: apis.google.com
- [Name Length: 15]
- [Label Count: 3]
- Type: AAAA (IPv6 Address) (28)
- Class: IN (0x0001)
- Answers
- apis.google.com: type CNAME, class IN, cname plus.l.google.com
- Name: apis.google.com
- Type: CNAME (Canonical NAME for an alias) (5)
- Class: IN (0x0001)
- Time to live: 21599
- Data length: 9
- CNAME: plus.l.google.com
- plus.l.google.com: type AAAA, class IN, addr 2607:f8b0:4001:c12::8a
- Name: plus.l.google.com
- Type: AAAA (IPv6 Address) (28)
- Class: IN (0x0001)
- Time to live: 299
- Data length: 16
- AAAA Address: 2607:f8b0:4001:c12::8a
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement