Wireshark mailing list archives

Re: Expert item for TCP RST flag


From: Joerg Mayer <jmayer () loplof de>
Date: Thu, 9 Jan 2014 13:29:07 +0100

On Tue, Jan 07, 2014 at 05:09:11PM -0800, Gerald Combs wrote:
On 1/7/14 4:19 PM, Joerg Mayer wrote:
Right now TCP packets with RST are marked as severity chat. Is there a reason
why this isn't warn?

Some applications use RSTs as a way to quickly close connections.
Internet Explorer is probably the most common example.

The reason for my question is that someone had network trouble and looked
at the error/warning items. Had RST been at that level, he would have found
the problem lots of work hours earlier - the RSTs were infdications of a
real problem.

So the question is: Do we allow lazy application writers to "hide" indications
of real problems in the network?

Ciao
 Jörg
-- 
Joerg Mayer                                           <jmayer () loplof de>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: