Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] How to identify session setup / confirmation

From: "Stringer, Rich (R.)" <rstring8@xxxxxxxx>
Date: Mon, 9 Mar 2009 08:57:11 -0400
Title: How to identify session setup / confirmation

Hello All,

I am trying to analyze packets between two Microsoft Biztalk servers.  I am looking for two things.
1.  1st server requesting a session with the 2nd server.
2.  Confirmation that the communication session is setup / ack'd.

This is the primary focus of my search.
3.  1st Biztalk sends an XML message to the 2nd Biztalk server.
4.  2nd Biztalk servers sends a response to the 1st Biztalk server ack'ing that the message was received.

What are the packet characteristics that I should be looking for?
What does the presence of the PSH, SYN, and ACK flags mean?

Thanks in advance,

Rich Stringer
Application Development Services - eHub Support
W2G237 iTek Center West, 15575 Lundy Parkway
Dearborn, MI  48126
(313) 317-7566 (Direct)

* rstring8@xxxxxxxx