No. Time Source Destination Protocol Length Info
66 6.550919000 192.168.178.25 107.20.203.175 TCP 78 49877 > ibm-mqisdp [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=16 TSval=601755386 TSecr=0 SACK_PERM=1
Frame 66: 78 bytes on wire (624 bits), 78 bytes captured (624 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:42.841398000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043662.841398000 seconds
[Time delta from previous captured frame: 0.000408000 seconds]
[Time delta from previous displayed frame: 0.000000000 seconds]
[Time since reference or first frame: 6.550919000 seconds]
Frame Number: 66
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0x60a4 (24740)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x308e [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 0, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 0 (relative sequence number)
Header length: 44 bytes
Flags: 0x002 (SYN)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...0 .... = Acknowledgment: Not set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish request (SYN): server port ibm-mqisdp]
[Message: Connection establish request (SYN): server port ibm-mqisdp]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
Checksum: 0xada7 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes), Maximum segment size, No-Operation (NOP), Window scale, No-Operation (NOP), No-Operation (NOP), Timestamps, SACK permitted, End of Option List (EOL)
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Window scale: 4 (multiply by 16)
Kind: Window Scale (3)
Length: 3
Shift count: 4
[Multiplier: 16]
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755386, TSecr 0
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755386
Timestamp echo reply: 0
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
End of Option List (EOL)
Type: 0
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0000 = Number: End of Option List (EOL) (0)
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 40 60 a4 40 00 40 06 30 8e c0 a8 b2 19 6b 14 .@`.@[email protected].
0020 cb af c2 d5 07 5b 6b ce 76 f9 00 00 00 00 b0 02 .....[k.v.......
0030 ff ff ad a7 00 00 02 04 05 b4 01 03 03 04 01 01 ................
0040 08 0a 23 de 0e fa 00 00 00 00 04 02 00 00 ..#...........
No. Time Source Destination Protocol Length Info
81 6.720133000 107.20.203.175 192.168.178.25 TCP 74 ibm-mqisdp > 49877 [SYN, ACK] Seq=0 Ack=1 Win=14480 Len=0 MSS=1460 SACK_PERM=1 TSval=518111328 TSecr=601755386 WS=256
Frame 81: 74 bytes on wire (592 bits), 74 bytes captured (592 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.010612000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.010612000 seconds
[Time delta from previous captured frame: 0.016024000 seconds]
[Time delta from previous displayed frame: 0.169214000 seconds]
[Time since reference or first frame: 6.720133000 seconds]
Frame Number: 81
Frame Length: 74 bytes (592 bits)
Capture Length: 74 bytes (592 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 60
Identification: 0x0000 (0)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0xad36 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 0, Ack: 1, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 0 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 40 bytes
Flags: 0x012 (SYN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port ibm-mqisdp]
[Message: Connection establish acknowledge (SYN+ACK): server port ibm-mqisdp]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 14480
[Calculated window size: 14480]
Checksum: 0x66bd [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
Timestamps: TSval 518111328, TSecr 601755386
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111328
Timestamp echo reply: 601755386
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Window scale: 8 (multiply by 256)
Kind: Window Scale (3)
Length: 3
Shift count: 8
[Multiplier: 256]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 66]
[The RTT to ACK the segment was: 0.169214000 seconds]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 3c 00 00 40 00 24 06 ad 36 6b 14 cb af c0 a8 .<..@.$..6k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 10 6b ce 76 fa a0 12 ...[......k.v...
0030 38 90 66 bd 00 00 02 04 05 b4 04 02 08 0a 1e e1 8.f.............
0040 c0 60 23 de 0e fa 01 03 03 08 .`#.......
No. Time Source Destination Protocol Length Info
82 6.720192000 192.168.178.25 107.20.203.175 TCP 66 49877 > ibm-mqisdp [ACK] Seq=1 Ack=1 Win=131760 Len=0 TSval=601755550 TSecr=518111328
Frame 82: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.010671000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.010671000 seconds
[Time delta from previous captured frame: 0.000059000 seconds]
[Time delta from previous displayed frame: 0.000059000 seconds]
[Time since reference or first frame: 6.720192000 seconds]
Frame Number: 82
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0xbe00 (48640)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0xd33d [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 1, Ack: 1, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 1 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xad4b [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755550, TSecr 518111328
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755550
Timestamp echo reply: 518111328
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 81]
[The RTT to ACK the segment was: 0.000059000 seconds]
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 34 be 00 40 00 40 06 d3 3d c0 a8 b2 19 6b 14 .4..@.@..=....k.
0020 cb af c2 d5 07 5b 6b ce 76 fa 91 f7 ae 11 80 10 .....[k.v.......
0030 20 2b ad 4b 00 00 01 01 08 0a 23 de 0f 9e 1e e1 +.K......#.....
0040 c0 60 .`
No. Time Source Destination Protocol Length Info
83 6.722567000 192.168.178.25 107.20.203.175 MQTT 96 CONNECT
Frame 83: 96 bytes on wire (768 bits), 96 bytes captured (768 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.013046000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.013046000 seconds
[Time delta from previous captured frame: 0.002375000 seconds]
[Time delta from previous displayed frame: 0.002375000 seconds]
[Time since reference or first frame: 6.722567000 seconds]
Frame Number: 83
Frame Length: 96 bytes (768 bits)
Capture Length: 96 bytes (768 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:mqtt]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 82
Identification: 0xbf22 (48930)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0xd1fd [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 1, Ack: 1, Len: 30
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 1 (relative sequence number)
[Next sequence number: 31 (relative sequence number)]
Acknowledgment number: 1 (relative ack number)
Header length: 32 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0x968f [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755551, TSecr 518111328
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755551
Timestamp echo reply: 518111328
[SEQ/ACK analysis]
[Bytes in flight: 30]
MQ Telemetry Transport, Message Type: CONNECT, QoS: 0
Fixed Header
0001 .... = Message Type: 0x01
.... 0... = DUP Flag: 0
.... .00. = QoS Level: 0
.... ...0 = Retain: 0
Remain Length: 28
Variable Header
Protocol Name: MQTT
Protocol Version: 4
Flags
0... .... = Username Flag: 0
.0.. .... = Password Flag: 0
..0. .... = Will Retain Flag: 0
...0 0... = Will QoS Flag: 0
.... .0.. = Will Flag: 0
.... ..1. = Clean Session Flag: 1
Keep Alive (secs): 60
Payload
Client ID: MQTTClient409362
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 52 bf 22 40 00 40 06 d1 fd c0 a8 b2 19 6b 14 .R."@[email protected].
0020 cb af c2 d5 07 5b 6b ce 76 fa 91 f7 ae 11 80 18 .....[k.v.......
0030 20 2b 96 8f 00 00 01 01 08 0a 23 de 0f 9f 1e e1 +........#.....
0040 c0 60 10 1c 00 04 4d 51 54 54 04 02 00 3c 00 10 .`....MQTT...<..
0050 4d 51 54 54 43 6c 69 65 6e 74 34 30 39 33 36 32 MQTTClient409362
No. Time Source Destination Protocol Length Info
98 6.891369000 107.20.203.175 192.168.178.25 TCP 66 ibm-mqisdp > 49877 [ACK] Seq=1 Ack=31 Win=14592 Len=0 TSval=518111371 TSecr=601755551
Frame 98: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.181848000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.181848000 seconds
[Time delta from previous captured frame: 0.017669000 seconds]
[Time delta from previous displayed frame: 0.168802000 seconds]
[Time since reference or first frame: 6.891369000 seconds]
Frame Number: 98
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x6e9a (28314)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3ea4 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 1, Ack: 31, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 1 (relative sequence number)
Acknowledgment number: 31 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xccf3 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111371, TSecr 601755551
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111371
Timestamp echo reply: 601755551
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 83]
[The RTT to ACK the segment was: 0.168802000 seconds]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 34 6e 9a 40 00 24 06 3e a4 6b 14 cb af c0 a8 .4n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 11 6b ce 77 18 80 10 ...[......k.w...
0030 00 39 cc f3 00 00 01 01 08 0a 1e e1 c0 8b 23 de .9............#.
0040 0f 9f ..
No. Time Source Destination Protocol Length Info
99 6.893587000 107.20.203.175 192.168.178.25 TCP 66 [TCP Dup ACK 98#1] ibm-mqisdp > 49877 [ACK] Seq=1 Ack=31 Win=14592 Len=0 TSval=518111372 TSecr=601755551
Frame 99: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.184066000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.184066000 seconds
[Time delta from previous captured frame: 0.002218000 seconds]
[Time delta from previous displayed frame: 0.002218000 seconds]
[Time since reference or first frame: 6.893587000 seconds]
Frame Number: 99
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x6e9b (28315)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3ea3 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 1, Ack: 31, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 1 (relative sequence number)
Acknowledgment number: 31 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xccf2 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111372, TSecr 601755551
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111372
Timestamp echo reply: 601755551
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 98]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 34 6e 9b 40 00 24 06 3e a3 6b 14 cb af c0 a8 .4n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 11 6b ce 77 18 80 10 ...[......k.w...
0030 00 39 cc f2 00 00 01 01 08 0a 1e e1 c0 8c 23 de .9............#.
0040 0f 9f ..
No. Time Source Destination Protocol Length Info
102 6.901793000 107.20.203.175 192.168.178.25 MQTT 70 CONNACK
Frame 102: 70 bytes on wire (560 bits), 70 bytes captured (560 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.192272000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.192272000 seconds
[Time delta from previous captured frame: 0.004170000 seconds]
[Time delta from previous displayed frame: 0.008206000 seconds]
[Time since reference or first frame: 6.901793000 seconds]
Frame Number: 102
Frame Length: 70 bytes (560 bits)
Capture Length: 70 bytes (560 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:mqtt]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 56
Identification: 0x6e9c (28316)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3e9e [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 1, Ack: 31, Len: 4
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 1 (relative sequence number)
[Next sequence number: 5 (relative sequence number)]
Acknowledgment number: 31 (relative ack number)
Header length: 32 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xace2 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111374, TSecr 601755551
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111374
Timestamp echo reply: 601755551
[SEQ/ACK analysis]
[Bytes in flight: 4]
MQ Telemetry Transport, Message Type: CONNACK, QoS: 0
Fixed Header
0010 .... = Message Type: 0x02
.... 0... = DUP Flag: 0
.... .00. = QoS Level: 0
.... ...0 = Retain: 0
Remain Length: 2
Payload
Payload Data: 0000
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 38 6e 9c 40 00 24 06 3e 9e 6b 14 cb af c0 a8 .8n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 11 6b ce 77 18 80 18 ...[......k.w...
0030 00 39 ac e2 00 00 01 01 08 0a 1e e1 c0 8e 23 de .9............#.
0040 0f 9f 20 02 00 00 .. ...
No. Time Source Destination Protocol Length Info
103 6.901848000 192.168.178.25 107.20.203.175 TCP 66 49877 > ibm-mqisdp [ACK] Seq=31 Ack=5 Win=131760 Len=0 TSval=601755725 TSecr=518111374
Frame 103: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.192327000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.192327000 seconds
[Time delta from previous captured frame: 0.000055000 seconds]
[Time delta from previous displayed frame: 0.000055000 seconds]
[Time since reference or first frame: 6.901848000 seconds]
Frame Number: 103
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x3946 (14662)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x57f8 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 31, Ack: 5, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 31 (relative sequence number)
Acknowledgment number: 5 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xac4c [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755725, TSecr 518111374
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755725
Timestamp echo reply: 518111374
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 102]
[The RTT to ACK the segment was: 0.000055000 seconds]
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 34 39 46 40 00 40 06 57 f8 c0 a8 b2 19 6b 14 .49F@[email protected].
0020 cb af c2 d5 07 5b 6b ce 77 18 91 f7 ae 15 80 10 .....[k.w.......
0030 20 2b ac 4c 00 00 01 01 08 0a 23 de 10 4d 1e e1 +.L......#..M..
0040 c0 8e ..
No. Time Source Destination Protocol Length Info
122 7.124032000 192.168.178.25 107.20.203.175 MQTT 68 DISCONNECT
Frame 122: 68 bytes on wire (544 bits), 68 bytes captured (544 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.414511000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.414511000 seconds
[Time delta from previous captured frame: 0.003836000 seconds]
[Time delta from previous displayed frame: 0.222184000 seconds]
[Time since reference or first frame: 7.124032000 seconds]
Frame Number: 122
Frame Length: 68 bytes (544 bits)
Capture Length: 68 bytes (544 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:mqtt]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 54
Identification: 0xf622 (63010)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x9b19 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 31, Ack: 5, Len: 2
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 31 (relative sequence number)
[Next sequence number: 33 (relative sequence number)]
Acknowledgment number: 5 (relative ack number)
Header length: 32 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xcb69 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755941, TSecr 518111374
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755941
Timestamp echo reply: 518111374
[SEQ/ACK analysis]
[Bytes in flight: 2]
MQ Telemetry Transport, Message Type: DISCONNECT, QoS: 0
Fixed Header
1110 .... = Message Type: 0x0e
.... 0... = DUP Flag: 0
.... .00. = QoS Level: 0
.... ...0 = Retain: 0
Remain Length: 0
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 36 f6 22 40 00 40 06 9b 19 c0 a8 b2 19 6b 14 .6."@[email protected].
0020 cb af c2 d5 07 5b 6b ce 77 18 91 f7 ae 15 80 18 .....[k.w.......
0030 20 2b cb 69 00 00 01 01 08 0a 23 de 11 25 1e e1 +.i......#..%..
0040 c0 8e e0 00 ....
No. Time Source Destination Protocol Length Info
124 7.126545000 192.168.178.25 107.20.203.175 TCP 66 49877 > ibm-mqisdp [FIN, ACK] Seq=33 Ack=5 Win=131760 Len=0 TSval=601755944 TSecr=518111374
Frame 124: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.417024000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.417024000 seconds
[Time delta from previous captured frame: 0.000992000 seconds]
[Time delta from previous displayed frame: 0.002513000 seconds]
[Time since reference or first frame: 7.126545000 seconds]
Frame Number: 124
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0xb6bb (46779)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0xda82 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 33, Ack: 5, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 33 (relative sequence number)
Acknowledgment number: 5 (relative ack number)
Header length: 32 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xab6e [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601755944, TSecr 518111374
Kind: Timestamp (8)
Length: 10
Timestamp value: 601755944
Timestamp echo reply: 518111374
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 34 b6 bb 40 00 40 06 da 82 c0 a8 b2 19 6b 14 .4..@[email protected].
0020 cb af c2 d5 07 5b 6b ce 77 1a 91 f7 ae 15 80 11 .....[k.w.......
0030 20 2b ab 6e 00 00 01 01 08 0a 23 de 11 28 1e e1 +.n......#..(..
0040 c0 8e ..
No. Time Source Destination Protocol Length Info
130 7.296167000 107.20.203.175 192.168.178.25 TCP 78 [TCP Dup ACK 102#1] ibm-mqisdp > 49877 [ACK] Seq=5 Ack=31 Win=14592 Len=0 TSval=518111472 TSecr=601755725 SLE=33 SRE=34
Frame 130: 78 bytes on wire (624 bits), 78 bytes captured (624 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.586646000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.586646000 seconds
[Time delta from previous captured frame: 0.001544000 seconds]
[Time delta from previous displayed frame: 0.169622000 seconds]
[Time since reference or first frame: 7.296167000 seconds]
Frame Number: 130
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0x6e9d (28317)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3e95 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 5, Ack: 31, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 5 (relative sequence number)
Acknowledgment number: 31 (relative ack number)
Header length: 44 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xcff2 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps, No-Operation (NOP), No-Operation (NOP), SACK
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111472, TSecr 601755725
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111472
Timestamp echo reply: 601755725
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
SACK: 33-34
left edge = 33 (relative)
right edge = 34 (relative)
[TCP SACK Count: 1]
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 102]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 40 6e 9d 40 00 24 06 3e 95 6b 14 cb af c0 a8 .@n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 15 6b ce 77 18 b0 10 ...[......k.w...
0030 00 39 cf f2 00 00 01 01 08 0a 1e e1 c0 f0 23 de .9............#.
0040 10 4d 01 01 05 0a 6b ce 77 1a 6b ce 77 1b .M....k.w.k.w.
No. Time Source Destination Protocol Length Info
131 7.296182000 107.20.203.175 192.168.178.25 TCP 66 ibm-mqisdp > 49877 [ACK] Seq=5 Ack=34 Win=14592 Len=0 TSval=518111472 TSecr=601755941
Frame 131: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.586661000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.586661000 seconds
[Time delta from previous captured frame: 0.000015000 seconds]
[Time delta from previous displayed frame: 0.000015000 seconds]
[Time since reference or first frame: 7.296182000 seconds]
Frame Number: 131
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x6e9e (28318)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3ea0 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 5, Ack: 34, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 5 (relative sequence number)
Acknowledgment number: 34 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xcb01 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111472, TSecr 601755941
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111472
Timestamp echo reply: 601755941
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 124]
[The RTT to ACK the segment was: 0.169637000 seconds]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 34 6e 9e 40 00 24 06 3e a0 6b 14 cb af c0 a8 .4n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 15 6b ce 77 1b 80 10 ...[......k.w...
0030 00 39 cb 01 00 00 01 01 08 0a 1e e1 c0 f0 23 de .9............#.
0040 11 25 .%
No. Time Source Destination Protocol Length Info
132 7.296218000 192.168.178.25 107.20.203.175 MQTT 68 [TCP Retransmission] DISCONNECT
Frame 132: 68 bytes on wire (544 bits), 68 bytes captured (544 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.586697000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.586697000 seconds
[Time delta from previous captured frame: 0.000036000 seconds]
[Time delta from previous displayed frame: 0.000036000 seconds]
[Time since reference or first frame: 7.296218000 seconds]
Frame Number: 132
Frame Length: 68 bytes (544 bits)
Capture Length: 68 bytes (544 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:mqtt]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 54
Identification: 0xe123 (57635)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0xb018 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 31, Ack: 5, Len: 2
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 31 (relative sequence number)
[Next sequence number: 33 (relative sequence number)]
Acknowledgment number: 5 (relative ack number)
Header length: 32 bytes
Flags: 0x019 (FIN, PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xca5b [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601756112, TSecr 518111472
Kind: Timestamp (8)
Length: 10
Timestamp value: 601756112
Timestamp echo reply: 518111472
[SEQ/ACK analysis]
[Bytes in flight: 3]
[TCP Analysis Flags]
[This frame is a (suspected) retransmission]
[Expert Info (Note/Sequence): Retransmission (suspected)]
[Message: Retransmission (suspected)]
[Severity level: Note]
[Group: Sequence]
[The RTO for this segment was: 0.169673000 seconds]
[RTO based on delta from frame: 124]
MQ Telemetry Transport, Message Type: DISCONNECT, QoS: 0
Fixed Header
1110 .... = Message Type: 0x0e
.... 0... = DUP Flag: 0
.... .00. = QoS Level: 0
.... ...0 = Retain: 0
Remain Length: 0
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 36 e1 23 40 00 40 06 b0 18 c0 a8 b2 19 6b 14 .6.#@[email protected].
0020 cb af c2 d5 07 5b 6b ce 77 18 91 f7 ae 15 80 19 .....[k.w.......
0030 20 2b ca 5b 00 00 01 01 08 0a 23 de 11 d0 1e e1 +.[......#.....
0040 c0 f0 e0 00 ....
No. Time Source Destination Protocol Length Info
133 7.296237000 192.168.178.25 107.20.203.175 TCP 66 [TCP Dup ACK 132#1] 49877 > ibm-mqisdp [ACK] Seq=34 Ack=5 Win=131760 Len=0 TSval=601756112 TSecr=518111472
Frame 133: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.586716000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.586716000 seconds
[Time delta from previous captured frame: 0.000019000 seconds]
[Time delta from previous displayed frame: 0.000019000 seconds]
[Time since reference or first frame: 7.296237000 seconds]
Frame Number: 133
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0xb239 (45625)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0xdf04 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 34, Ack: 5, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 34 (relative sequence number)
Acknowledgment number: 5 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xaa64 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601756112, TSecr 518111472
Kind: Timestamp (8)
Length: 10
Timestamp value: 601756112
Timestamp echo reply: 518111472
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 132]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence]
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 34 b2 39 40 00 40 06 df 04 c0 a8 b2 19 6b 14 .4.9@[email protected].
0020 cb af c2 d5 07 5b 6b ce 77 1b 91 f7 ae 15 80 10 .....[k.w.......
0030 20 2b aa 64 00 00 01 01 08 0a 23 de 11 d0 1e e1 +.d......#.....
0040 c0 f0 ..
No. Time Source Destination Protocol Length Info
135 7.296908000 107.20.203.175 192.168.178.25 TCP 66 ibm-mqisdp > 49877 [FIN, ACK] Seq=5 Ack=34 Win=14592 Len=0 TSval=518111473 TSecr=601755941
Frame 135: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.587387000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.587387000 seconds
[Time delta from previous captured frame: 0.000260000 seconds]
[Time delta from previous displayed frame: 0.000671000 seconds]
[Time since reference or first frame: 7.296908000 seconds]
Frame Number: 135
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x6e9f (28319)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3e9f [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 5, Ack: 34, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 5 (relative sequence number)
Acknowledgment number: 34 (relative ack number)
Header length: 32 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xcaff [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111473, TSecr 601755941
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111473
Timestamp echo reply: 601755941
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 132]
[The RTT to ACK the segment was: 0.000690000 seconds]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 34 6e 9f 40 00 24 06 3e 9f 6b 14 cb af c0 a8 .4n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 15 6b ce 77 1b 80 11 ...[......k.w...
0030 00 39 ca ff 00 00 01 01 08 0a 1e e1 c0 f1 23 de .9............#.
0040 11 25 .%
No. Time Source Destination Protocol Length Info
136 7.296941000 192.168.178.25 107.20.203.175 TCP 66 49877 > ibm-mqisdp [ACK] Seq=34 Ack=6 Win=131760 Len=0 TSval=601756112 TSecr=518111473
Frame 136: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.587420000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.587420000 seconds
[Time delta from previous captured frame: 0.000033000 seconds]
[Time delta from previous displayed frame: 0.000033000 seconds]
[Time since reference or first frame: 7.296941000 seconds]
Frame Number: 136
Frame Length: 66 bytes (528 bits)
Capture Length: 66 bytes (528 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9), Dst: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Destination: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 192.168.178.25 (192.168.178.25), Dst: 107.20.203.175 (107.20.203.175)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 52
Identification: 0x355a (13658)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: TCP (6)
Header checksum: 0x5be4 [validation disabled]
[Good: False]
[Bad: False]
Source: 192.168.178.25 (192.168.178.25)
Destination: 107.20.203.175 (107.20.203.175)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 49877 (49877), Dst Port: ibm-mqisdp (1883), Seq: 34, Ack: 6, Len: 0
Source port: 49877 (49877)
Destination port: ibm-mqisdp (1883)
[Stream index: 8]
Sequence number: 34 (relative sequence number)
Acknowledgment number: 6 (relative ack number)
Header length: 32 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 8235
[Calculated window size: 131760]
[Window size scaling factor: 16]
Checksum: 0xaa62 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 601756112, TSecr 518111473
Kind: Timestamp (8)
Length: 10
Timestamp value: 601756112
Timestamp echo reply: 518111473
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 135]
[The RTT to ACK the segment was: 0.000033000 seconds]
0000 24 65 11 6e 6c b5 7c c3 a1 b5 bb d9 08 00 45 00 $e.nl.|.......E.
0010 00 34 35 5a 40 00 40 06 5b e4 c0 a8 b2 19 6b 14 .45Z@.@.[.....k.
0020 cb af c2 d5 07 5b 6b ce 77 1b 91 f7 ae 16 80 10 .....[k.w.......
0030 20 2b aa 62 00 00 01 01 08 0a 23 de 11 d0 1e e1 +.b......#.....
0040 c0 f1 ..
No. Time Source Destination Protocol Length Info
137 7.464318000 107.20.203.175 192.168.178.25 TCP 78 [TCP Dup ACK 135#1] ibm-mqisdp > 49877 [ACK] Seq=6 Ack=34 Win=14592 Len=0 TSval=518111515 TSecr=601756112 SLE=31 SRE=34
Frame 137: 78 bytes on wire (624 bits), 78 bytes captured (624 bits) on interface 0
Interface id: 0
Encapsulation type: Ethernet (1)
Arrival Time: Jun 29, 2014 14:07:43.754797000 CEST
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1404043663.754797000 seconds
[Time delta from previous captured frame: 0.167377000 seconds]
[Time delta from previous displayed frame: 0.167377000 seconds]
[Time since reference or first frame: 7.464318000 seconds]
Frame Number: 137
Frame Length: 78 bytes (624 bits)
Capture Length: 78 bytes (624 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: Bad TCP]
[Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update]
Ethernet II, Src: Avm_6e:6c:b5 (24:65:11:6e:6c:b5), Dst: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Destination: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
Address: Apple_b5:bb:d9 (7c:c3:a1:b5:bb:d9)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
Address: Avm_6e:6c:b5 (24:65:11:6e:6c:b5)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 107.20.203.175 (107.20.203.175), Dst: 192.168.178.25 (192.168.178.25)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 64
Identification: 0x6ea0 (28320)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 36
Protocol: TCP (6)
Header checksum: 0x3e92 [validation disabled]
[Good: False]
[Bad: False]
Source: 107.20.203.175 (107.20.203.175)
Destination: 192.168.178.25 (192.168.178.25)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: ibm-mqisdp (1883), Dst Port: 49877 (49877), Seq: 6, Ack: 34, Len: 0
Source port: ibm-mqisdp (1883)
Destination port: 49877 (49877)
[Stream index: 8]
Sequence number: 6 (relative sequence number)
Acknowledgment number: 34 (relative ack number)
Header length: 44 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 57
[Calculated window size: 14592]
[Window size scaling factor: 256]
Checksum: 0xce42 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (24 bytes), No-Operation (NOP), No-Operation (NOP), Timestamps, No-Operation (NOP), No-Operation (NOP), SACK
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
Timestamps: TSval 518111515, TSecr 601756112
Kind: Timestamp (8)
Length: 10
Timestamp value: 518111515
Timestamp echo reply: 601756112
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
SACK: 31-34
left edge = 31 (relative)
right edge = 34 (relative)
[TCP SACK Count: 1]
[SEQ/ACK analysis]
[TCP Analysis Flags]
[This is a TCP duplicate ack]
[Duplicate ACK #: 1]
[Duplicate to the ACK in frame: 135]
[Expert Info (Note/Sequence): Duplicate ACK (#1)]
[Message: Duplicate ACK (#1)]
[Severity level: Note]
[Group: Sequence]
0000 7c c3 a1 b5 bb d9 24 65 11 6e 6c b5 08 00 45 00 |.....$e.nl...E.
0010 00 40 6e a0 40 00 24 06 3e 92 6b 14 cb af c0 a8 .@n.@.$.>.k.....
0020 b2 19 07 5b c2 d5 91 f7 ae 16 6b ce 77 1b b0 10 ...[......k.w...
0030 00 39 ce 42 00 00 01 01 08 0a 1e e1 c1 1b 23 de .9.B..........#.
0040 11 d0 01 01 05 0a 6b ce 77 18 6b ce 77 1b ......k.w.k.w.