FTP data is identified as window update in Wireshark

Posted on 2011-09-14
Medium Priority
Last Modified: 2012-06-21
In the expert info composite screen the ftp data packets show up as windows update?

Group        Protocol     Summary                Count
Sequence  TCP            Window Update     37856

Is this normal? Does the wireshark dissector not identify FTP data correctly?

Or do I have a lot of windows update traffic on the network?
Question by:Dragon0x40
  • 2
  • 2

Accepted Solution

netjgrnaut earned 2000 total points
ID: 36539309
A TCP Window Update packet should not be confused with a "Microsoft Windows Update" packet (which Wireshark wouldn't identify as such, anyway).

Explanation from http://ask.wireshark.org/questions/901/expertmessage-window-update...

A packet marked "TCP Window Update" simply indicates that the sender's TCP receive buffer space has increased. Look at the previous packet from the sender - note the Window Size value in the TCP header. Then look at the "TCP Window Update" packet's Window Size setting.

What triggers these "TCP Window Update" packets? When an application picks up data from the receive buffer there is now more receive buffer space available. Wireshark sees the Window Size field value has increased and marks it to let you know the Window Size field has increased.

This is normal network behavior. Problem behaviors would be Zero Window conditions.

Hope that helps!

Author Comment

ID: 36539392
In the experts infos:

I have no errors

I have these warnings:

Window is full   20

Zero Window   17

ACKed lost segment (common at capture start)  63

Previous segment los (common st caputre start)  78

Out-Of-Order segment   187

Fast retransmission (suspected)  14

This was on a 1gb ftp file transfer

Expert Comment

ID: 36539494
Is this a new question?

Wireshark is not mis-identifying your FTP traffic.
The Window Update packet has nothing to do with MS Windows Update.

So... what's the question?

Author Comment

ID: 36539527
I will open a new question.

Featured Post

Train for your Pen Testing Engineer Certification

Enroll today in this bundle of courses to gain experience in the logistics of pen testing, Linux fundamentals, vulnerability assessments, detecting live systems, and more! This series, valued at $3,000, is free for Premium members, Team Accounts, and Qualified Experts.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Network ports are the threads that hold network communication together. They are an essential part of networking that can be easily ignore or misunderstood, my goals is to show those who don't have a strong network foundation how network ports opera…
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question