Need help understanding CWR

asked 2018-12-12 09:07:38 +0000

echo gravatar image


I am trying to get my head around a capture between two Windows 2008r2 machines. The machines negotiate to support CWR in the handshake. I've got access to only one of them and yes, there are a bunch packets with the bit for CWR set coming from the other server. Googling around learns that it's the ROUTER in between systems who sets this if it's queues get full. But in this case, there are no routers between the systems (possibly some switches though).

Question: Can switches set this flag too, or is it the server itself maybe? Also: How many packets with this flag set should be considered acceptable?

edit retag flag offensive close merge delete