cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1110
Views
0
Helpful
4
Replies

Capture Output

I am trying to read the capture output that I am getting.  I know that the S=Syn, A=Ack, P=Push (What does PUSH mean?) but what does a dot (.) and a F stand for.  I am using the command show cap capin to get the information. 

 

116: 08:41:51.820514 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159159008 win 65280
117: 08:41:51.820697 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: P 2159168509:2159168689(180) ack 3968189402 win 23172
118: 08:41:51.820727 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159160468 win 65280
119: 08:41:51.820788 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: . 2159168689:2159169969(1280) ack 3968189402 win 23172
120: 08:41:51.820788 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: P 2159169969:2159171091(1122) ack 3968189402 win 23172
121: 08:41:51.820804 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: P 2159171091:2159172371(1280) ack 3968189402 win 23172
122: 08:41:51.821002 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: P 2159172371:2159172530(159) ack 3968189402 win 23172
123: 08:41:51.821048 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159162870 win 65280
124: 08:41:51.821124 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159164309 win 65280
125: 08:41:51.821292 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159165769 win 65280
126: 08:41:51.821338 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: . 2159172530:2159173810(1280) ack 3968189402 win 23172
127: 08:41:51.821338 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.5.38.64959: P 2159173810:2159174850(1040) ack 3968189402 win 23172
128: 08:41:51.821383 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159167229 win 65280
129: 08:41:51.825930 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54128: F 64380739:64380739(0) ack 1606964975 win 10076
130: 08:41:51.825946 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54101: F 2796087050:2796087050(0) ack 1225516994 win 14028
131: 08:41:51.826007 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54098: F 2302808906:2302808906(0) ack 2216340728 win 12033
132: 08:41:51.826022 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54100: F 2986425331:2986425331(0) ack 2874897291 win 15216
133: 08:41:51.826037 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54157: F 323375547:323375547(0) ack 1481009295 win 6456
134: 08:41:51.826037 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.9.223.54105: F 3252855761:3252855761(0) ack 951598908 win 15949
135: 08:41:51.840212 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: . 1714258375:1714259114(739) ack 3096216603 win 5079
136: 08:41:51.840227 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: . 1714259114:1714259988(874) ack 3096216603 win 5079
137: 08:41:51.840242 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: . 1714259988:1714261268(1280) ack 3096216603 win 5079
138: 08:41:51.840242 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: P 1714261268:1714261288(20) ack 3096216603 win 5079
139: 08:41:51.840441 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: P 1714261288:1714262568(1280) ack 3096216603 win 5079
140: 08:41:51.840578 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: P 1714262568:1714262588(20) ack 3096216603 win 5079
141: 08:41:51.840990 802.1Q vlan#2114 P0 10.28.39.93.443 > 10.28.16.15.61245: P 1714262588:1714262755(167) ack 3096216603 win 5079
142: 08:41:51.855958 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159168689 win 65280
143: 08:41:51.856431 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159171091 win 65280
144: 08:41:51.856751 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159172530 win 65280
145: 08:41:51.857331 802.1Q vlan#2114 P0 10.28.5.38.64959 > 10.28.39.93.443: . ack 2159174850 win 65280
146: 08:41:51.858888 802.1Q vlan#2114 P0 10.28.16.15.61245 > 10.28.39.93.443: . ack 1714259988 win 65280
147: 08:41:51.859086 802.1Q vlan#2114 P0 10.28.16.15.61245 > 10.28.39.93.443: . ack 1714261288 win 65280

1 Accepted Solution

Accepted Solutions

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

The dot is an ACK flag, and the F is a FIN, ACK .

 

Why don't you dump the capture to PCAP, it would be easier to read:

 

copy /pcap capture:XXXX ftp://x.x.x.x/FOO.pcap

 

cheers,

Seb.

View solution in original post

4 Replies 4

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

The dot is an ACK flag, and the F is a FIN, ACK .

 

Why don't you dump the capture to PCAP, it would be easier to read:

 

copy /pcap capture:XXXX ftp://x.x.x.x/FOO.pcap

 

cheers,

Seb.

Man I had a full brain freeze I could not think of what the F was.  I knew that 3 way hand shake but completely went blank today.  Thank you.  I don't have a FTP server in the organization that I can use but working on getting one for other things so will just use it once the server team gets it build for me to try out the command you had in the reply.

 

Thanks again!

What does Push mean in this case I had never heard that term used.  The only reason I put it was push was because it was in another tread I had found.

Take a look at the TCP RFC: https://tools.ietf.org/html/rfc793

...page 46 under the send and receive commands is detail on the PUSH flag.

 

cheers,

Seb.

Review Cisco Networking for a $25 gift card