A situation
You open a packet capture to find out why a web page will not load. Each TCP segment shows a list of fields: flags, sequence numbers, a window size and more. To read the capture, you need to know what each field means. The good news is that there are only about a dozen.
What it is
Every TCP segment starts with a header: a block of control information in front of the data. It is at least 20 bytes and at most 60 bytes, depending on how many options it carries. The diagram shows it in rows of 32 bits (4 bytes), the way the standards (RFCs) draw it.
What each field does
| Field | Size | Job |
|---|---|---|
| Source / destination port | 16 bits each | Which application sent the segment and which one should receive it |
| Sequence number | 32 bits | The number of the first data byte in this segment |
| Acknowledgement number | 32 bits | The next byte the sender of this segment expects to receive (valid when ACK is set) |
| Data offset | 4 bits | Header length in 4-byte words: 5 means 20 bytes, 15 means 60 |
| Flags | 8 bits | On/off bits that show what kind of segment this is |
| Window | 16 bits | How many more bytes the sender of this segment can receive right now |
| Checksum | 16 bits | Detects damaged headers or data; a damaged segment is discarded |
| Urgent pointer | 16 bits | Marks urgent data when URG is set; rarely used today |
| Options | 0–40 bytes | Extras such as MSS, window scaling, SACK and timestamps |
The flags
A flag is a single bit that is either on (1) or off (0). You will see these six classic flags most often:
| Flag | Meaning | Seen in |
|---|---|---|
SYN | Synchronise: “I want to start a connection; here is my first sequence number” | The first two handshake messages |
ACK | The acknowledgement number is valid | Every segment after the first SYN |
FIN | Finish: “I have no more data to send” | Closing a connection |
RST | Reset: “stop now; this connection is not valid” | Refused or broken connections |
PSH | Push: pass this data to the application straight away | Data segments |
URG | The urgent pointer field is valid | Rare |
The other two flags, CWR and ECE, are used by Explicit Congestion Notification (ECN), a way for routers to warn about congestion without dropping packets.
- 1. Opening: only SYN is set. The acknowledgement number is not used yet.
- 2. Reply: SYN and ACK are both set: the server starts its side of the connection and acknowledges the client's SYN.
- 3. Data: a normal data segment has ACK set, often with PSH.
- 4. Closing: FIN says this side has finished sending.
Why it is built this way
Each feature of TCP needs a field. Reliable delivery needs sequence and acknowledgement numbers. Flow control needs the window. Setting up and closing a connection needs the flags. That is why the TCP header is at least 20 bytes, while the UDP header, which offers almost none of these features, is only 8 bytes. The options area has let TCP gain new features over the years without changing the fixed part.
How to see it
A packet capture tool such as Wireshark decodes the header for you. Below is the first segment of a connection (a SYN). It is an example written for this lesson, not captured from a real network.
Transmission Control Protocol, Src Port: 52000, Dst Port: 443
Source Port: 52000
Destination Port: 443
Sequence Number (raw): 1520031250
Acknowledgment Number (raw): 0
1010 .... = Header Length: 40 bytes (10)
Flags: 0x002 (SYN)
Window: 64240
Checksum: 0x5c1a
Urgent Pointer: 0
Options: (20 bytes), Maximum segment size, SACK permitted,
Timestamps, No-Operation (NOP), Window scaleCheck yourself
In a capture, the data offset field of a TCP segment is 5. How long is its TCP header?
A capture shows a connection that ends suddenly, with no orderly closing exchange. Which flag was most likely in the last segment?
A receiver's buffer is almost full and it wants the sender to slow down. Which header field does it use to say how much more data it can accept?