Ethereal-dev: Re: [Ethereal-dev] TCP Seq graph and users' guide.

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Richard Sharpe <rsharpe@xxxxxxxxxx>
Date: Tue, 19 Nov 2002 07:37:19 +1030 (CST)
On Mon, 18 Nov 2002, John McDermott wrote:

> All,
> I recently received a query about how to interpret the Time-Sequence 
> Graph (Stevens).  I thought, "Well, rtfm...".  Looking at the users quide 
> for the tools menu 
> (http://www.ethereal.com/docs/user-guide/ch03toolssection.html) despite 
> saying that it is for 0.9.7, it does not have "TCP Stream Analysis" in 
> the screen capture or the text.
> 
> Absent material in the documentation, can someone tell me how to 
> interpret this?  I don't use that feature so I'm a bit unsure.

Hmmm, you too, eh.

If you select a TCP packet you can get some neat graphs which seem to show 
how sequence numbers progress on the stream.

It seems that the person who asked was really looking for the packet that 
caused the remote end to close the window (or what she thought was the 
packet).

I suggested a filter expression that should locate the acks where the 
window was closed, and that she ask the questions on the Ethereal-users 
mailing list.

The pictures have not been updated for a while, either.

Regards
-----
Richard Sharpe, rsharpe@xxxxxxxxxx, rsharpe@xxxxxxxxx, 
sharpe@xxxxxxxxxxxx, http://www.richardsharpe.com