Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] TCP Window Update

From: Xtrolyte <xtrolyte@xxxxxxxxx>
Date: Wed, 2 Jan 2008 19:43:13 -0600
In doing some analysis with Wireshark, I've been seeing a lot of TCP Window Update packets. I understand the basics of what this means....as in the source and destination changing their TCP receive windows to adjust for the amount of data each can handle. Is this understanding correct? Also, in a normal capture, should I see a lot of these. What is it a sign of when I see a ton of these in a capture?
 
Cheers.