A situation
You download a 3 MB photo. It travels as thousands of separate TCP segments. Some take different paths, some arrive late, and once in a while one is lost. Yet the photo you receive is perfect, with every byte in the right place. Two numbers in the TCP header make this possible.
What it is
TCP numbers bytes, not segments. The sequence number in each segment is the number of the first data byte it carries. If a segment starts at byte 1001 and carries 1000 bytes, it holds bytes 1001 to 2000, and the next segment starts at 2001.
The receiver replies with an acknowledgement number (ACK): the number of the next byte it expects. “ACK 2001” means “I have everything up to byte 2000; send 2001 next”. Because it confirms everything before that byte at once, it is called a cumulative acknowledgement.
| Segment | Sequence number | Data bytes | Bytes covered | ACK the receiver sends |
|---|---|---|---|---|
| 1 | 1001 | 1000 | 1001–2000 | 2001 |
| 2 | 2001 | 1000 | 2001–3000 | 3001 |
| 3 | 3001 | 500 | 3001–3500 | 3501 |
How much data fits in one segment? That is the maximum segment size (MSS), which each side announces during the three-way handshake. On Ethernet it is usually 1460 bytes: the 1500-byte maximum packet size (MTU) minus 20 bytes of IPv4 header and 20 bytes of TCP header.
When a segment is lost
- 1. Segment 1 arrives. The receiver replies with ACK 2001.
- 2. Segment 2 is lost. A busy router drops it, so the receiver never sees it.
- 3. Segment 3 arrives out of order. The receiver keeps it, but there is a gap, so it can only send ACK 2001 again.
- 4. Duplicate ACKs. Each later segment triggers another ACK 2001. Three duplicates tell the sender where the missing data starts.
- 5. Retransmission. The sender resends bytes 2001–3000. The gap is filled, so the receiver's next ACK confirms all the data it now holds.
The sender has two ways to notice a loss:
- Retransmission timeout (RTO): when the sender sends data, it starts a timer. If no ACK covers that data before the timer runs out, it sends the data again. The length of the timer is based on how long ACKs have recently been taking to arrive.
- Fast retransmit: three duplicate ACKs for the same number suggest that one segment is missing while later ones got through. The sender resends it immediately, without waiting for the timer.
Most systems also support selective acknowledgement (SACK), a TCP option in which the receiver lists the blocks of data it already has. The sender then resends only the missing data, not everything after it.
Why it works this way
Numbering bytes instead of segments lets TCP split or combine data freely and still know exactly what is missing. The receiver holds out-of-order segments in a buffer and passes data to the application only in order, with no gaps. The application never sees a lost or out-of-order segment, just a clean stream of bytes. The cost is delay: one lost segment holds up all the data behind it until the retransmission arrives.
How to verify it
Cisco IOS keeps counters for TCP sessions that end on the router itself, such as SSH or BGP sessions. The output below is based on Cisco documentation, not captured from a lab device, and is shortened.
R1#show tcp statistics Rcvd: 2150 Total, 0 no port 0 checksum error, 0 bad offset, 0 too short 1432 packets (186210 bytes) in sequence 3 dup packets (1460 bytes) 2 out-of-order packets (2920 bytes) 5 dup ack packets, 0 ack packets with unsend data 1208 ack packets (96644 bytes) Sent: 2311 Total, 0 urgent packets 14 control packets (including 1 retransmitted) 1502 data packets (204118 bytes) 4 data packets (5840 bytes) retransmitted 790 ack only packets (402 delayed)
Check yourself
During a download, a segment arrives with sequence number 4001 and carries 1460 bytes. Nothing is missing. What acknowledgement number does the receiver send?
After its first ACK 7001, the sender receives three more ACKs, all with the number 7001. What does the sender do?
During a file download, segment 5 arrives before segment 4. What does TCP pass to the application at that moment?