Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

FTP data is identified as window update in Wireshark

Posted on 2011-09-14
4
Medium Priority
?
765 Views
Last Modified: 2012-06-21
In the expert info composite screen the ftp data packets show up as windows update?

Group        Protocol     Summary                Count
Sequence  TCP            Window Update     37856

Is this normal? Does the wireshark dissector not identify FTP data correctly?

Or do I have a lot of windows update traffic on the network?
0
Comment
Question by:Dragon0x40
  • 2
  • 2
4 Comments
 
LVL 6

Accepted Solution

by:
netjgrnaut earned 2000 total points
ID: 36539309
A TCP Window Update packet should not be confused with a "Microsoft Windows Update" packet (which Wireshark wouldn't identify as such, anyway).

Explanation from http://ask.wireshark.org/questions/901/expertmessage-window-update...

A packet marked "TCP Window Update" simply indicates that the sender's TCP receive buffer space has increased. Look at the previous packet from the sender - note the Window Size value in the TCP header. Then look at the "TCP Window Update" packet's Window Size setting.

What triggers these "TCP Window Update" packets? When an application picks up data from the receive buffer there is now more receive buffer space available. Wireshark sees the Window Size field value has increased and marks it to let you know the Window Size field has increased.

This is normal network behavior. Problem behaviors would be Zero Window conditions.

Hope that helps!
0
 

Author Comment

by:Dragon0x40
ID: 36539392
In the experts infos:

I have no errors

I have these warnings:

Window is full   20

Zero Window   17

ACKed lost segment (common at capture start)  63

Previous segment los (common st caputre start)  78

Out-Of-Order segment   187

Fast retransmission (suspected)  14

This was on a 1gb ftp file transfer
0
 
LVL 6

Expert Comment

by:netjgrnaut
ID: 36539494
Is this a new question?

Wireshark is not mis-identifying your FTP traffic.
The Window Update packet has nothing to do with MS Windows Update.

So... what's the question?
0
 

Author Comment

by:Dragon0x40
ID: 36539527
I will open a new question.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question