Anyone,
I have been looking at captures and many times I see at the end of an TCP HTTP session a TCP packet that looks to (in wireshark) change the window size. Why does wireshark show that the window size changes right before the TCP session is closed? It does not make sense to change the window size after the first FIN,ACK ACK exchange has been done as there is nothing to do after that except for close the connection!
Please see the PMP file for an example snapshot of the capture I am talking about.
Thanks!
George
Attachment:
http.bmp
Description: Windows bitmap