Wireshark mailing list archives

Re: Expert item for TCP RST flag


From: Edwin Groothuis <edwin.groothuis () riverbed com>
Date: Thu, 09 Jan 2014 20:11:56 +1100

On 8/01/14 12:09 , Gerald Combs wrote:
On 1/7/14 4:19 PM, Joerg Mayer wrote:
Right now TCP packets with RST are marked as severity chat. Is there a reason
why this isn't warn?

Some applications use RSTs as a way to quickly close connections.
Internet Explorer is probably the most common example.

A host will also send a RST when it gets more data after it has send a
FIN. (But this might be the specific TCP stack I have seen this
behaviour on)

TCP RST is not something I'm worried about.

Edwin

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: