Monday, June 24, 2019

Very new to Wireshark - question re TCP ACK entries

I've got a packet capture from a PC which I got by mirroring their switch port and capturing on a laptop connected to another port.

What I'm seeing are a lot of TCP ACK entries, ACKed unseen segments and retransmissions from completely different computers on another part of the network, on a completely different switch.

Should I be seeing these as I thought they should be unicast between the source and destination and nothing to do with the computer I'm monitoring?

Thanks



No comments:

Post a Comment