This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi

Does anyone know why a Server (10.161.96.228) sends two TCP RST after a successfull termination of the session with FIN/ACK from both the Server and the Client (10.90.32.180?

Is this normal, as i see it also in other sessions (X11, etc.)

Regards, Patrick

alt text

asked 26 Sep '17, 04:23

kehlpat's gravatar image

kehlpat
6112
accept rate: 0%


I would say there's nothing to worry about, unless there should have been more data - but since both sides already said goodbye via FIN the RSTs won't do no harm. It's hard to say where they come from, but maybe a device between the endpoints created them, e.g. a Firewall. This could be checked by looking at the TTL - if it's the same for the RSTs as for the normal packets from the IP it's the endpoint doing this.

permanent link

answered 26 Sep '17, 04:49

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×27

question asked: 26 Sep '17, 04:23

question was seen: 2,306 times

last updated: 26 Sep '17, 04:49

p​o​w​e​r​e​d by O​S​Q​A