Wireshark mailing list archives

Re: Window scaling


From: "Maynard, Chris" <Christopher.Maynard () IGT com>
Date: Wed, 1 Jun 2016 18:26:01 +0000

Robert Dahlem <Robert.Dahlem@...> writes:

The packet signals a Window size of 8,192, but also a Window Scale of 8
(multiply by 256), which would give my a Calculated window size of
2,097,152.

But my Wireshark 1.12.8 tells me "Calculated window size: 8192" which
would match with the firewalls behaviour.

Is there something wrong with the SYN/ACK packet?

No, there's nothing wrong with the SYN/ACK packet, at least as far as I can tell.  SYN packets are never themselves 
scaled so Wireshark will always display the calculated window size the same as the window size value, regardless of the 
scaling factor.

What's missing here though is the client's SYN packet showing its scaling factor, but I suspect that the client does 
not support scaling, which means there is no window scaling effect in either direction.

From https://tools.ietf.org/html/rfc7323#section-2.2:

   This option is an offer, not a promise; both sides MUST send Window
   Scale options in their <SYN> segments to enable window scaling in
   either direction.

- Chris
P.S. This response may get posted twice.  I always try to respond using gmane first in an attempt to avoid the annoying 
company disclaimer from being appended to the e-mail; however, gmane has been extremely unreliable for me lately, so 
I'm resending it since it appears the original response was lost.

-- 






CONFIDENTIALITY NOTICE: This message is the property of International Game Technology PLC and/or its subsidiaries and 
may contain proprietary, confidential or trade secret information.  This message is intended solely for the use of the 
addressee.  If you are not the intended recipient and have received this message in error, please delete this message 
from your system. Any unauthorized reading, distribution, copying, or other use of this message or its attachments is 
strictly prohibited.

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: