Frame Number: 12
- geninfo General information
- num Number
- len Frame Length
- caplen Captured Length
- timestamp Captured Time
- frame Frame 12: 156 bytes on wire (1248 bits), 156 bytes captured (1248 bits) on interface 0
- frame.interface_id Interface id: 0
- frame.encap_type Encapsulation type: Ethernet (1)
- frame.time Arrival Time: Dec 20, 2004 06:20:34.866413000 Eastern Standard Time
- frame.offset_shift Time shift for this packet: 0.000000000 seconds
- frame.time_epoch Epoch Time: 1103541634.866413000 seconds
- frame.time_delta Time delta from previous captured frame: 0.081473000 seconds
- frame.time_delta_displayed Time delta from previous displayed frame: 0.081473000 seconds
- frame.time_relative Time since reference or first frame: 0.813275000 seconds
- frame.number Frame Number: 12
- frame.len Frame Length: 156 bytes (1248 bits)
- frame.cap_len Capture Length: 156 bytes (1248 bits)
- frame.marked Frame is marked: False
- frame.ignored Frame is ignored: False
- frame.protocols Protocols in frame: eth:ip:tcp:ldap:gss-api:spnego-krb5
- eth Ethernet II, Src: Vmware_f0:6b:d1 (00:0c:29:f0:6b:d1), Dst: Vmware_09:4d:fa (00:0c:29:09:4d:fa)
- eth.dst Destination: Vmware_09:4d:fa (00:0c:29:09:4d:fa)
- eth.addr Address: Vmware_09:4d:fa (00:0c:29:09:4d:fa)
- eth.lg .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- eth.ig .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- eth.src Source: Vmware_f0:6b:d1 (00:0c:29:f0:6b:d1)
- eth.addr Address: Vmware_f0:6b:d1 (00:0c:29:f0:6b:d1)
- eth.lg .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- eth.ig .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- eth.type Type: IP (0x0800)
- ip Internet Protocol Version 4, Src: 172.31.1.104 (172.31.1.104), Dst: 172.31.1.101 (172.31.1.101)
- ip.version Version: 4
- ip.hdr_len Header length: 20 bytes
- ip.dsfield Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
- ip.dsfield.dscp 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- ip.dsfield.ecn .... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
- ip.len Total Length: 142
- ip.id Identification: 0xb610 (46608)
- ip.flags Flags: 0x02 (Don't Fragment)
- ip.flags.rb 0... .... = Reserved bit: Not set
- ip.flags.df .1.. .... = Don't fragment: Set
- ip.flags.mf ..0. .... = More fragments: Not set
- ip.frag_offset Fragment offset: 0
- ip.ttl Time to live: 128
- ip.proto Protocol: TCP (6)
- ip.checksum Header checksum: 0xe94d [validation disabled]
- ip.checksum_good Good: False
- ip.checksum_bad Bad: False
- ip.src Source: 172.31.1.104 (172.31.1.104)
- ip.addr Source or Destination Address: 172.31.1.104 (172.31.1.104)
- ip.src_host Source Host: 172.31.1.104
- ip.host Source or Destination Host: 172.31.1.104
- ip.dst Destination: 172.31.1.101 (172.31.1.101)
- ip.addr Source or Destination Address: 172.31.1.101 (172.31.1.101)
- ip.dst_host Destination Host: 172.31.1.101
- ip.host Source or Destination Host: 172.31.1.101
- Source GeoIP: Unknown
- Destination GeoIP: Unknown
- tcp Transmission Control Protocol, Src Port: mctet-gateway (3116), Dst Port: ldap (389), Seq: 1713, Ack: 2392, Len: 102
- tcp.srcport Source port: mctet-gateway (3116)
- tcp.dstport Destination port: ldap (389)
- tcp.port Source or Destination Port: 3116
- tcp.port Source or Destination Port: 389
- tcp.stream Stream index: 0
- tcp.len TCP Segment Len: 102
- tcp.seq Sequence number: 1713 (relative sequence number)
- tcp.nxtseq Next sequence number: 1815 (relative sequence number)
- tcp.ack Acknowledgment number: 2392 (relative ack number)
- tcp.hdr_len Header length: 20 bytes
- tcp.flags Flags: 0x018 (PSH, ACK)
- tcp.flags.res 000. .... .... = Reserved: Not set
- tcp.flags.ns ...0 .... .... = Nonce: Not set
- tcp.flags.cwr .... 0... .... = Congestion Window Reduced (CWR): Not set
- tcp.flags.ecn .... .0.. .... = ECN-Echo: Not set
- tcp.flags.urg .... ..0. .... = Urgent: Not set
- tcp.flags.ack .... ...1 .... = Acknowledgment: Set
- tcp.flags.push .... .... 1... = Push: Set
- tcp.flags.reset .... .... .0.. = Reset: Not set
- tcp.flags.syn .... .... ..0. = Syn: Not set
- tcp.flags.fin .... .... ...0 = Fin: Not set
- tcp.window_size_value Window size value: 64049
- tcp.window_size Calculated window size: 64049
- tcp.window_size_scalefactor Window size scaling factor: -2 (no window scaling used)
- tcp.checksum Checksum: 0xa3a4 [validation disabled]
- tcp.checksum_good Good Checksum: False
- tcp.checksum_bad Bad Checksum: False
- tcp.analysis SEQ/ACK analysis
- tcp.analysis.acks_frame This is an ACK to the segment in frame: 11
- tcp.analysis.ack_rtt The RTT to ACK the segment was: 0.081473000 seconds
- tcp.analysis.bytes_in_flight Bytes in flight: 102
- tcp.pdu.size PDU Size: 102
- ldap Lightweight Directory Access Protocol
- ldap.sasl_buffer_length SASL Buffer Length: 98
- SASL Buffer
- gss-api GSS-API Generic Security Service Application Program Interface
- gss-api.OID OID: 1.2.840.113554.1.2.2 (KRB5 - Kerberos 5)
- spnego.krb5.blob krb5_blob: 020111001000ffff75b15340fbb34295ad58191d21416129...
- spnego.krb5.tok_id krb5_tok_id: KRB5_GSS_Wrap (0x0102)
- spnego.krb5.sgn_alg krb5_sgn_alg: HMAC (0x0011)
- spnego.krb5.seal_alg krb5_seal_alg: RC4 (0x0010)
- spnego.krb5.snd_seq krb5_snd_seq: 75b15340fbb34295
- spnego.krb5.sgn_cksum krb5_sgn_cksum: ad58191d21416129
- spnego.krb5.confounder krb5_confounder: eb7ee0027d0a5393
- GSS-API Encrypted payload (53 bytes)