Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So let’s look at a more complete example. 2
In this example, host A initiates a session with the source port of 1024 3
in a destination port of 23, in other words telnet. 4
Host A sends 10 bytes of data and an initial sequence number of 10. 5
Host B acknowledges receipt of the 10 bytes 6
by sending an acknowledgement number back to A of 11. 7
Host B in this example, also sets its initial sequence number to 5. 8
please note also that the port numbers are reversed 8
the source port for traffic going from B to A is 23 and the destination port is 1024. 9
In this example because we’re using a sliding window 10
A may send 250 bytes of data for example. 11
So notice the sequence number is incremented to 260. 12
In previous examples, we’ve use easy numbers 13
the window size of 1 or window size of 3 but please note in reality 14
window sizes are set to the amount of data that can be transmitted in bytes. 15
So this may not be as easy to read as sequences of 1, 2, and 3. 16
receipt of data up to sequence 5 and thus acknowledging sequence number 6. 17
The source ports are swap round again 18
so the source port is 1024 and the destination port is 23. 19
Now host B is acknowledging for sequence number 261 20
remember A send 10 bytes and the 250 bytes 21
so in other words 260 bytes of data. 22
B is sending sequence number 6 and once again the port numbers are reversed. 23
It’s a very important that you understand, how source and destination ports work 24
So on that note there is nothing better than showing you real world example using Wireshark. 25
So I’m going to capture traffic on my network 26
and then I’m going to go to for instance google.com with my web browser. 27
I’ll go back to Wireshark and stop the capture, here's an example is the DNS query. 28
So we’ve got host 10.0.0.1 which is my machine 29
a Dell laptop, querying the DNS server. 30
At layer 2, you can see the source is my Dell machine going to my Cisco router. 31
This is an Ethernet 2 frame and please note the type field. 32
At layer 2 as mentioned, the type field specifies the protocol at layer 3. 33
In this case 0x0800 in hexadecimal specifies that the layer 3 protocol is IPv4. 34
At layer 3 you can see the source IP address and the destination IP address. 35
My PC and the DNS server, you can see that this is IPv4 36
you can see the header length is 20 bytes. 37
DSCP or Differentiated Services Code Points is not used in this example 38
notice ECN which is to do with explicit congestion notification 39
I mentioned that briefly when talking about the TCP header. 42
What I’d like you to see here is notice the protocol at layer 4 is UDP 40
that values in hexadecimal, so 11 in hexadecimal is equal to 17 41
the protocol number once again for UDP is 17. 42
So at layer 4, we can see that User Datagram Protocol or UDP is being used. 43
The source port is 62249, in other words, a dynamic or ephemeral port 44
going to a destination port of 53 in other words DNS. 45
We can see the port numbers once again, and opening up the DNS query 46
we can see that it was a query, looking for specific host address. 47
Here we have a DNS response from the DNS server to my host. 48
So once again, very quickly at layer 2 49
you can see the type field denotes the protocol at layer 3. 50
At layer 3, the protocol field, tells us which protocol is used at layer 4 51
Here’s another DNS query from my host to the DNS server. 52
And if we open up the DNS query information 53
you can see that it’s a query for google.com 54
and it's a host query, notice type A, the DNS server replies 55
and notice in the answer, it give us the IP address of google.com 56
Now here’s the three-way handshake between my machine and Google. 57
Notice the source is 10.0.0.1 58
and the destination is this IP address which is Google. 59
Notice the source port is 58313 destinations is 80 64
in other words I’m opening up a web connection to a web server. 60
Opening that up, you can see once again the source and destination port numbers 61
but notice here the flag that are set is SYN. 62
So opening that up you can see that 63
all the other flags or bit set to 0 except for the SYN bit 64
and opening that up you can see, we are trying to set up a connection to the server 65
so we’ve got a connection establish request message to the server. 66
No other flags are set. Notice the initial window size is 8192 67
and opening up the options, you can see that the MSS or Maximum Segment Size is set to 1460 bytes. 68
The reply from Google to my machine at layer 4 shows that the source port is 80 69
and the destination port is 58313. 70
Opening that up, notice the flags that are set are SYN ACK 71
so it’s a second part of the three-way handshake. 72
Notice the acknowledgement bit is set and the synchronization bit is set 73
opening that up, you can see that it's a connection establish acknowledgment from Google. 74
Notice the window size request is 5720 and if we open up the options 75
notice here the maximum segment size is 1430. 76
Looking at the last part of three-way handshake 77
notice my machine talking to Google 78
opening up TCP, you can see that the flags that are set is just the acknowledgement bit 79
and the window size requested 64350 85
and looking at the sequence acknowledgment analysis 80
notice that this is an acknowledgement. 81
Going back to the first step of the three-way hand shake 82
notice that the initial sequence number from my machine to Google is set to 0. 83
Going to the actual TCP header, notice the sequence number 0. 84
Googles reply as a sequence number 0 and the acknowledgement of 1. 85
As you can see here as well. 86
So they are letting us know, the next segment that they expect to receive is segment 1. 87
Our acknowledgement to them, is we are sending sequence number 1 88
and we are acknowledging the sequence number 1. 89
This is as per what we discussed. 90
Later on, when HTTP is being received 91
notice, we are receiving information from Google to our machine its TCP 92
and notice here, this is a TCP segment of the re-assembled Protocol Data Unit. 93
In other words this is a fragment. 94
Looking at TCP, we can see the sources HTTP and the destination is our port number. 95
In other words Google is sending traffic to us 96
notice here that the sequence number is 2861 97
the next sequence number is 3798 98
and the acknowledgement number is 944. 99
so the next sequence number remember is 3798 100
going to the very next part of the capture 101
notice the sequence number here is 3798 and the next sequence number is 5228. 102
And notice there’s an acknowledgement from our machine to Google 103
saying that we expect to receive 5228. 104
And then the very next capture you can see 105
that sequence number 5228, were sent from Google to us. 106
The next sequence number is 6658, which is the next piece received. 107
Notice 6658 is the sequence number received. 114
Our host is acknowledging receipt of that 108
and saying that the next bit of data to receive is 7894 109
going to the next capture, you can see that the sequence number is what Google sent to us. 110
Now without boring you any longer 111
I’m hoping that this capture gives you a little bit of insight 112
into what's actually happening on the wire. 113
wirehark remembers a free application that you can download 114
just search for it on the internet 115
now I suggest that you captures some traffic on your machine 116
so that you can actually see what's going on in the back ground. 117
So what have we covered? 118
In this section we look at the 2 main protocols residing at layer 4. 119
UDP or User Datagram Protocol and TCP or Transmission Control Protocol. 120
I explained port numbers and which port numbers would be used in which scenarios. 121
I explained the TCP three-way handshake 122
I explained windowing and I explained sequence numbers. 123
Thank you for watching!
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.