在连接建立时对需要进行同步的序号,ACK 表示 |
应答字段标志。关于这两个概念可参考: |
linux-xh53:~ # tcpdump -i eth0 port 22 -S -vv
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
09:54:32.927057 IP (tos 0x0, ttl 64, id 18765, offset 0, flags [DF], proto TCP (6), length 52)
192.168.1.100.ecsqdmn > 192.168.1.104.ssh: Flags [S], cksum 0xc57d (correct), seq 3731693470, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0
09:54:32.927090 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 52)
192.168.1.104.ssh > 192.168.1.100.ecsqdmn: Flags [S.], cksum 0x8443 (incorrect -> 0x00f6), seq 4262702424, ack 3731693471, win 14600, options [mss 1460,nop,nop,sackOK,nop,wscale 4], length 0
09:54:32.927468 IP (tos 0x0, ttl 64, id 18766, offset 0, flags [DF], proto TCP (6), length 40)
192.168.1.100.ecsqdmn > 192.168.1.104.ssh: Flags [.], cksum 0x69b1 (correct), seq 3731693471, ack 4262702425, win 4380, length 0
09:54:32.949513 IP (tos 0x0, ttl 64, id 34270, offset 0, flags [DF], proto TCP (6), length 61)
欢迎光临 曲径通幽论坛 (http://www.groad.net/bbs/) | Powered by Discuz! X3.2 |