Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] SYN Retransmissions

From: "Sheahan, John" <John.Sheahan@xxxxxxxxxxxxx>
Date: Fri, 27 Jun 2008 18:52:12 -0400
thanks alot for the info, Luis...that really helps

john 

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Luis EG
Ontanon
Sent: Friday, June 27, 2008 12:13 PM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] SYN Retransmissions

Usually a SYN is retransmitted at least 3 times.

Dependingon the OS you might or no have parameters to set this aspects
of TCP behaviour.

Usually you have a retransmit timer (Trtx) and an abort timer (Tabrt) to
set up.

The SYN will be retransmitted after some time related to Trtx (N * Trtx
+ K) as many times as possible until Tabrt expires.

How this is done changes between OSs.

BSDs uses the following sysctl's
  net.inet.tcp.keepinit
  net.inet.tcp.rexmit_{min,slop}

Solaris uses the parameter
   tcp_rexmit_interval_initial

I do not know how this is set-up in Linux or Windows.


On Fri, Jun 27, 2008 at 5:50 PM, Sheahan, John
<John.Sheahan@xxxxxxxxxxxxx> wrote:
> I have a general question about SYN retransmissions.
> I am troubleshooting a problem whereby an initial SYN is sent but 
> unanswered so the client sends one SYN retransmission, when that goes 
> unanswered, no more SYNs are sent by the client.
>
> Is this normal behavior or can this be tuned?
>
> I would expect (hope) that the client would retransmitt the SYN more 
> than once.
>
> thanks
>
> john
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
>
>



--
This information is top security. When you have read it, destroy
yourself.
-- Marshall McLuhan
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users