Wireshark-dev: Re: [Wireshark-dev] Expert item for TCP RST flag
From: Joerg Mayer <jmayer@xxxxxxxxx>
Date: Thu, 9 Jan 2014 13:40:33 +0100
On Tue, Jan 07, 2014 at 05:09:11PM -0800, Gerald Combs wrote:
> On 1/7/14 4:19 PM, Joerg Mayer wrote:
> > Right now TCP packets with RST are marked as severity chat. Is there a reason
> > why this isn't warn?
> 
> Some applications use RSTs as a way to quickly close connections.
> Internet Explorer is probably the most common example.

Just curious: How does an application do that (rst instead of proper
fin-sequence)? Kill the process that opened the tcp socket?

Ciao
   Jörg
-- 
Joerg Mayer                                           <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.