Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.1.2 (2 of 20 in this unit)35 of 84 in the Network Fundamentals course

The TCP header

Each field in a TCP segment header, and the job it does.

Intermediate · 7 min read

TCP header is the block of control fields at the start of every TCP segment, 20 bytes long without options and up to 60 bytes with them. It carries the source and destination ports, the sequence and acknowledgement numbers, flags such as SYN, ACK and FIN, the window size and a checksum.

In simple terms: It is the label on each TCP segment. It says which applications are talking, where this piece fits in the stream, what the segment is for and how much more data the receiver can accept.

A situation

You open a packet capture to find out why a web page will not load. Each TCP segment shows a list of fields: flags, sequence numbers, a window size and more. To read the capture, you need to know what each field means. The good news is that there are only about a dozen.

What it is

Every TCP segment starts with a header: a block of control information in front of the data. It is at least 20 bytes and at most 60 bytes, depending on how many options it carries. The diagram shows it in rows of 32 bits (4 bytes), the way the standards (RFCs) draw it.

Source port16 bits
Destination port16 bits
Sequence number32 bits
Acknowledgement number32 bits
Data offset4 bitsheader length
Reserved4 bits
Flags8 bitsCWR ECE URG ACK PSH RST SYN FIN
Window16 bits
Checksum16 bits
Urgent pointer16 bits
Options (if any)0–40 bytes
The TCP header. The first five rows (20 bytes) are always present. Options can add up to 40 more bytes.

What each field does

FieldSizeJob
Source / destination port16 bits eachWhich application sent the segment and which one should receive it
Sequence number32 bitsThe number of the first data byte in this segment
Acknowledgement number32 bitsThe next byte the sender of this segment expects to receive (valid when ACK is set)
Data offset4 bitsHeader length in 4-byte words: 5 means 20 bytes, 15 means 60
Flags8 bitsOn/off bits that show what kind of segment this is
Window16 bitsHow many more bytes the sender of this segment can receive right now
Checksum16 bitsDetects damaged headers or data; a damaged segment is discarded
Urgent pointer16 bitsMarks urgent data when URG is set; rarely used today
Options0–40 bytesExtras such as MSS, window scaling, SACK and timestamps

The flags

A flag is a single bit that is either on (1) or off (0). You will see these six classic flags most often:

FlagMeaningSeen in
SYNSynchronise: “I want to start a connection; here is my first sequence number”The first two handshake messages
ACKThe acknowledgement number is validEvery segment after the first SYN
FINFinish: “I have no more data to send”Closing a connection
RSTReset: “stop now; this connection is not valid”Refused or broken connections
PSHPush: pass this data to the application straight awayData segments
URGThe urgent pointer field is validRare

The other two flags, CWR and ECE, are used by Explicit Congestion Notification (ECN), a way for routers to warn about congestion without dropping packets.

Client192.168.1.20:52000RouterServer203.0.113.10:443
  1. 1. Opening: only SYN is set. The acknowledgement number is not used yet.
  2. 2. Reply: SYN and ACK are both set: the server starts its side of the connection and acknowledges the client's SYN.
  3. 3. Data: a normal data segment has ACK set, often with PSH.
  4. 4. Closing: FIN says this side has finished sending.

Why it is built this way

Each feature of TCP needs a field. Reliable delivery needs sequence and acknowledgement numbers. Flow control needs the window. Setting up and closing a connection needs the flags. That is why the TCP header is at least 20 bytes, while the UDP header, which offers almost none of these features, is only 8 bytes. The options area has let TCP gain new features over the years without changing the fixed part.

How to see it

A packet capture tool such as Wireshark decodes the header for you. Below is the first segment of a connection (a SYN). It is an example written for this lesson, not captured from a real network.

Example decoded TCP header, as a capture tool shows it
Transmission Control Protocol, Src Port: 52000, Dst Port: 443
    Source Port: 52000
    Destination Port: 443
    Sequence Number (raw): 1520031250
    Acknowledgment Number (raw): 0
    1010 .... = Header Length: 40 bytes (10)
    Flags: 0x002 (SYN)
    Window: 64240
    Checksum: 0x5c1a
    Urgent Pointer: 0
    Options: (20 bytes), Maximum segment size, SACK permitted,
             Timestamps, No-Operation (NOP), Window scale
What to look for: Header Length: 40 bytes (10) is the data offset. 10 × 4 = 40 bytes: 20 fixed bytes plus 20 bytes of options. Flags: 0x002 (SYN) shows that only SYN is on, so this is the first message of the handshake. That is also why Acknowledgment Number is 0: the ACK flag is off, so the field is not used yet. The Options line lists what this client offers, such as its MSS and SACK support.

Check yourself

Predict · scenario 1

In a capture, the data offset field of a TCP segment is 5. How long is its TCP header?

Predict · scenario 2

A capture shows a connection that ends suddenly, with no orderly closing exchange. Which flag was most likely in the last segment?

Predict · scenario 3

A receiver's buffer is almost full and it wants the sender to slow down. Which header field does it use to say how much more data it can accept?