While looking at packet captured from netscalar device found a strange 2 way handshake where first packet was syn followed by syn-ack but third packet was ack with psh bit set and had data in it.Can anyone explain this? asked 26 Nov '13, 23:05 kishan pandey |
2 Answers:
This is allowed for TCP. Depends on the specific application implementation, the 3rd packet is allowed to carry application level data. Although this kind of cases are not much, but it was not uncommon in recent days. answered 27 Nov '13, 00:36 SteveZhou |
This is actually very common these days. It is still a 3 way handshake (ACK, PSH) but the application is also sending data as pointed out by @Zhoucengchao. answered 28 Nov '13, 20:10 Ken15 |