Wireshark not showing all "TCP window full"?
Hi,
With this PCAP file, Wireshark (v2.6.0) shows 4 "TCP Window Full" events using the display filter "tcp.analysis.window_full".
However, I was calculating the remaining window size on my own and I have found one more "TCP Window Full" event, right in the beginning of the TCP stream.
Packet no. 68 (TCP SYN/ACK) sets the window size (downlink) to 14480 bytes. Then there are 10 x HTTP data packets (uplink, no. 70 - 79), all containing 1448 bytes of data.
With packet no. 79, I would expect a "TCP Window Full" event, visible with display filter "tcp.analysis.window_full". Can somebody explain why it doesn't?
Many thanks!
Can't download your file - could you share it on cloudshark.org instead?
Great, didn't know cloudshark.org... Here is the file