|reply to funchords |
Re: How to test how many connections are being reset by RST pack
Using the following filter string
"(ip.src != your.ip.addr.ess) and (tcp.flags.reset == 1)"
I was able to get a steady display of incoming resets. Of course most would be normal. However looking at the list, which ones should I consider to be suspect?
John M. Wilson
Yarmouth Port, MA
The ones where Seq>1 and Ack>1 in the display (generally this means that data has already passed both ways, even if it was just a handshake).