Lay_Hin_53714
Dec 19, 2008Nimbostratus
tcpdump output interpret guide
Hi All,
Is there a document that can explain the output from tcpdump?
For example, I would like to know what S, P and DF means.
15:23:27.351280 202.6.123.44.9632 > 203.116.162.168.ldap: S 2450604975:2450604975(0) win 49640 (DF)
15:23:27.361003 203.116.162.168.ldap > 202.6.123.44.9632: S 3804777917:3804777917(0) ack 2450604976 win 1460 (DF)
15:23:27.361984 202.6.123.44.9632 > 203.116.162.168.ldap: . ack 1 win 49640 (DF)
15:23:27.423022 202.6.123.44.9632 > 203.116.162.168.ldap: P 1:149(148) ack 1 win 49640 (DF)
15:23:29.034865 203.116.162.168.ldap > 202.6.123.44.9632: . ack 149 win 8760 (DF)
15:23:29.133984 203.116.162.168.ldap > 202.6.123.44.9632: P 1:1461(1460) ack 149 win 8760 (DF)