This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello everyone,

I got some strange situation in Wireshark. When I sniffing traffic between my PC and some website, it appears that my PC request multiple connection to that website all at once, before any of this connections to be accepted by the server. What can be the issue?

There is a picture of this: (BTW I'm using Windows 10) alt text

Also, for not asking in new question, I want to ask how TCP creates Streams and why one connection to the same server use to have more Stream.

Thank you in advance

asked 22 May '17, 11:50

Nicola%20Tesla's gravatar image

Nicola Tesla
11225
accept rate: 0%

edited 22 May '17, 11:54


That's something you see when a browser starts multiple connections to pull various elements from the web server, and the round trip time is higher than just a few milliseconds. In that case the SYNs are sent on their way before the first SYN/ACKs come back. It's absolutely normal.

TCP creates stream/connections based on what the application wants - so if the application asks TCP to open multiple connections, TCP will do just that. And its usually to parallelize the requests to get content faster.

permanent link

answered 22 May '17, 11:55

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×82
×41
×11

question asked: 22 May '17, 11:50

question was seen: 1,062 times

last updated: 22 May '17, 11:55

p​o​w​e​r​e​d by O​S​Q​A