How does 'Follow TCP Stream' work
How does this feature work?
Occurs to me that perhaps it tracks source / destination IP addresses plus TCP Port numbers ... or perhaps it peers at TSVal and TSecr ... or perhaps it uses a mix of both.
[I am trying to follow a TCP Stream in two pcaps, one take on the internal side of a PAT Router, the other taken on the external side ... and the result isn't as wonderful as I was imagining it would be ... so now I want to understand how this feature works, so I can better understand the discrepancies I am seeing.]
--sk