| From |
To |
Protocol |
Details |
| 7.1. CL uses ARP to find MAC address for 10.1.1.1, its DNS server |
| CL |
DC |
ARP |
ARP:Request, 10.1.1.4 asks for 10.1.1.1 |
| DC |
CL |
ARP |
ARP:Response, 10.1.1.1 at 00-15-5D-6C-0D-06 |
| 7.2. CL queries DNS for “dc.josebda.local”, gets 10.1.1.1 |
| CL |
DC |
DNS |
DNS:QueryId = 0x36AE, QUERY (Standard query), Query for DC.josebda.local of type Host Addr on class Internet |
| DC |
CL |
DNS |
DNS:QueryId = 0x36AE, QUERY (Standard query), Response - Success, 10.1.1.1 |
| 7.3. CL negotiates a TCP session with DC on port 445 (SMB) |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49274, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1348427785, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Microsoft-DS(445), DstPort=49274, PayloadLen=0, Seq=806692608, Ack=1348427786, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49274, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1348427786, Ack=806692609, Win=513 (scale factor 0x8) = 131328 |
| 7.4. CL and DC negotiate an SMB session (note that DC offers SMB2 and CL takes it) |
| CL |
DC |
SMB |
SMB:C; Negotiate, Dialect = PC NETWORK PROGRAM 1.0, LANMAN1.0, Windows for Workgroups 3.1a, LM1.2X002, LANMAN2.1, NT LM 0.12, SMB 2.002 |
| DC |
CL |
SMB2 |
SMB2:R NEGOTIATE (0x0), GUID={83C66016-F309-B5A1-42A3-3B37BF0AE071}, Mid = 0 |
| 7.5. CL talks to the DC on port (88) to get a set of Kerberos tickets. First, the client Authentication for the domain |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49275, DstPort=Kerberos(88), PayloadLen=0, Seq=2790774373, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Kerberos(88), DstPort=49275, PayloadLen=0, Seq=2481525383, Ack=2790774374, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49275, DstPort=Kerberos(88), PayloadLen=0, Seq=2790774374, Ack=2481525384, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
KerberosV5 |
KerberosV5:AS Request Cname: administrator Realm: JOSEBDA.LOCAL Sname: krbtgt/JOSEBDA.LOCAL |
| DC |
CL |
KerberosV5 |
KerberosV5:AS Response Ticket[Realm: JOSEBDA.LOCAL, Sname: krbtgt/JOSEBDA.LOCAL] |
| DC |
CL |
TCP |
TCP:[Continuation to #451]Flags=...AP..., SrcPort=Kerberos(88), DstPort=49275, PayloadLen=51, Seq=2481526844 - 2481526895, Ack=2790774692, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49275, DstPort=Kerberos(88), PayloadLen=0, Seq=2790774692, Ack=2481526895, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49275, DstPort=Kerberos(88), PayloadLen=0, Seq=2790774692, Ack=2481526895, Win=513 (scale factor 0x8) = 131328 |
| 7.6. CL requests a Kerberos service authorization ticket to present to DC.joseba.local for cifs service |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49276, DstPort=Kerberos(88), PayloadLen=0, Seq=1217473064, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Kerberos(88), DstPort=49276, PayloadLen=0, Seq=51552186, Ack=1217473065, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49275, PayloadLen=0, Seq=2481526895, Ack=2790774693, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Kerberos(88), DstPort=49275, PayloadLen=0, Seq=2481526895, Ack=2790774693, Win=0 (scale factor 0x8) = 0 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49276, DstPort=Kerberos(88), PayloadLen=0, Seq=1217473065, Ack=51552187, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
KerberosV5 |
KerberosV5:TGS Request Realm: JOSEBDA.LOCAL Sname: cifs/DC.josebda.local |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49276, PayloadLen=0, Seq=51552187, Ack=1217474637, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
KerberosV5 |
KerberosV5:TGS Response Cname: Administrator |
| DC |
CL |
TCP |
TCP:[Continuation to #462]Flags=...AP..., SrcPort=Kerberos(88), DstPort=49276, PayloadLen=118, Seq=51553647 - 51553765, Ack=1217474637, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49276, DstPort=Kerberos(88), PayloadLen=0, Seq=1217474637, Ack=51553765, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49276, DstPort=Kerberos(88), PayloadLen=0, Seq=1217474637, Ack=51553765, Win=513 (scale factor 0x8) = 131328 |
| 7.7. CL asks DC for another Kerberos ticket |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49277, DstPort=Kerberos(88), PayloadLen=0, Seq=2381120000, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49276, PayloadLen=0, Seq=51553765, Ack=1217474638, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Kerberos(88), DstPort=49276, PayloadLen=0, Seq=51553765, Ack=1217474638, Win=0 (scale factor 0x8) = 0 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Kerberos(88), DstPort=49277, PayloadLen=0, Seq=1880462364, Ack=2381120001, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49277, DstPort=Kerberos(88), PayloadLen=0, Seq=2381120001, Ack=1880462365, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
KerberosV5 |
KerberosV5:TGS Request Realm: JOSEBDA.LOCAL Sname: krbtgt/JOSEBDA.LOCAL |
| DC |
CL |
KerberosV5 |
KerberosV5:TGS Response Cname: Administrator |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49277, DstPort=Kerberos(88), PayloadLen=0, Seq=2381121446, Ack=1880463823, Win=507 (scale factor 0x8) = 129792 |
| 7.8. SMB session with DC is setup. (while the last ACKs for the DC are still coming) |
| CL |
DC |
SMB2 |
SMB2:C SESSION SETUP (0x1), Mid = 1 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49277, PayloadLen=0, Seq=1880463823, Ack=2381121447, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49274, PayloadLen=0, Seq=806692849, Ack=1348430973, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Kerberos(88), DstPort=49277, PayloadLen=0, Seq=1880463823, Ack=2381121447, Win=0 (scale factor 0x8) = 0 |
| DC |
CL |
SMB2 |
SMB2:R SESSION SETUP (0x1) ,SessionFlags=0x0, Mid = 1 |
| 7.9. CL connects to tree \\dc.josebda.local\IPC$, asks DFS for a referral for “josebda.local”, then “\josebda.local\ns1” |
| CL |
DC |
SMB2 |
SMB2:C TREE CONNECT (0x3), Path=\\DC.josebda.local\IPC$, Mid = 2 |
| DC |
CL |
SMB2 |
SMB2:R TREE CONNECT (0x3), TID=0x1, Mid = 2 |
| CL |
DC |
DFS |
DFS:Get DFS Referral Request, FileName: josebda.local, MaxReferralLevel: 3 |
| DC |
CL |
DFS |
DFS:Get DFS Referral Response, NumberOfReferrals: 1 VersionNumber: 3 |
| CL |
DC |
DFS |
DFS:Get DFS Referral Request, FileName: \josebda.local\ns1, MaxReferralLevel: 4 |
| DC |
CL |
DFS |
DFS:Get DFS Referral Response, NumberOfReferrals: 1 VersionNumber: 4 |
| 7.11. CL now knows that it needs to talk to “ns.josebda.local”. Queries DNS to find it’s “10.1.1.2”, then ARP |
| CL |
DC |
DNS |
DNS:QueryId = 0xA941, QUERY (Standard query), Query for NS.josebda.local of type Host Addr on class Internet |
| DC |
CL |
DNS |
DNS:QueryId = 0xA941, QUERY (Standard query), Response - Success, 10.1.1.2 |
| CL |
NS |
ARP |
ARP:Request, 10.1.1.4 asks for 10.1.1.2 |
| NS |
CL |
ARP |
ARP:Response, 10.1.1.2 at 00-15-5D-6C-0D-04 |
| 7.12. CL negotiates a TCP session with NS on port 445 (SMB) |
| CL |
NS |
TCP |
TCP:Flags=......S., SrcPort=49278, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1616429650, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| NS |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Microsoft-DS(445), DstPort=49278, PayloadLen=0, Seq=802553199, Ack=1616429651, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
NS |
TCP |
TCP:Flags=...A...., SrcPort=49278, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1616429651, Ack=802553200, Win=513 (scale factor 0x8) = 131328 |
| 7.13. CL negotiates an SMB session with NS (selects SMB2 dialect) |
| CL |
NS |
SMB |
SMB:C; Negotiate, Dialect = PC NETWORK PROGRAM 1.0, LANMAN1.0, Windows for Workgroups 3.1a, LM1.2X002, LANMAN2.1, NT LM 0.12, SMB 2.002 |
| NS |
CL |
SMB2 |
SMB2:R NEGOTIATE (0x0), GUID={9832F94A-1CD3-61B4-40A3-F01305CCDB7E}, Mid = 0 |
| 7.14. CL requests a Kerberos service authorization ticket to present to NS.joseba.local for cifs service |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49279, DstPort=Kerberos(88), PayloadLen=0, Seq=2584167390, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Kerberos(88), DstPort=49279, PayloadLen=0, Seq=2711096963, Ack=2584167391, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49279, DstPort=Kerberos(88), PayloadLen=0, Seq=2584167391, Ack=2711096964, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
KerberosV5 |
KerberosV5:TGS Request Realm: JOSEBDA.LOCAL Sname: cifs/NS.josebda.local |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49279, PayloadLen=0, Seq=2711096964, Ack=2584168963, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
KerberosV5 |
KerberosV5:TGS Response Cname: Administrator |
| DC |
CL |
TCP |
TCP:[Continuation to #499]Flags=...AP..., SrcPort=Kerberos(88), DstPort=49279, PayloadLen=118, Seq=2711098424 - 2711098542, Ack=2584168963, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49279, DstPort=Kerberos(88), PayloadLen=0, Seq=2584168963, Ack=2711098542, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49279, DstPort=Kerberos(88), PayloadLen=0, Seq=2584168963, Ack=2711098542, Win=513 (scale factor 0x8) = 131328 |
| 7.15. SMB session with NS is setup. (while the last ACKs for the DC are still coming) |
| CL |
NS |
SMB2 |
SMB2:C SESSION SETUP (0x1), Mid = 1 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49279, PayloadLen=0, Seq=2711098542, Ack=2584168964, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Kerberos(88), DstPort=49279, PayloadLen=0, Seq=2711098542, Ack=2584168964, Win=0 (scale factor 0x8) = 0 |
| NS |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49278, PayloadLen=0, Seq=802553440, Ack=1616431432, Win=513 (scale factor 0x8) = 131328 |
| NS |
CL |
SMB2 |
SMB2:R SESSION SETUP (0x1) ,SessionFlags=0x0, Mid = 1 |
| 7.16. CL connects to tree \\ns\NS1, opens and queries information for josebda.local\ns1 and josebda.local\ns1\folder1. Error 599 on the last response indicates we need a referral |
| CL |
NS |
SMB2 |
SMB2:C TREE CONNECT (0x3), Path=\\NS\NS1, Mid = 2 |
| NS |
CL |
SMB2 |
SMB2:R TREE CONNECT (0x3), TID=0x1, Mid = 2 |
| CL |
NS |
SMB2 |
SMB2:C CREATE (0x5), Name=josebda.local\ns1@#510, Context=DHnQ, Context=MxAc, Context=QFid, Mid = 3 |
| NS |
CL |
SMB2 |
SMB2:R CREATE (0x5), Context=MxAc, Context=QFid, FID=0xFFFFFFFF00000001, Mid = 3 |
| CL |
NS |
SMB2 |
SMB2:C QUERY INFORMATION (0x10), FID=0xFFFFFFFF00000001, InformationClass=Query FS Volume Info, FID=0xFFFFFFFF00000001, Mid = 4 |
| NS |
CL |
SMB2 |
SMB2:R QUERY INFORMATION (0x10), Mid = 4 |
| CL |
NS |
SMB2 |
SMB2:C CLOSE (0x6), FID=0xFFFFFFFF00000001, Mid = 6 |
| NS |
CL |
SMB2 |
SMB2:R CLOSE (0x6), Mid = 6 |
| CL |
NS |
SMB2 |
SMB2:C CREATE (0x5), Name=josebda.local\ns1\folder1@#516, Context=DHnQ, Context=MxAc, Context=QFid, Mid = 7 |
| NS |
CL |
SMB2 |
SMB2:R , Mid = 7 - NT Status: System - Error, Code = (599) STATUS_PATH_NOT_COVERED |
| 7.17. CL connects to tree \\ns\IPC$, asks DFS for a referral for “\NS\ns1\folder1” (note via ARP that NS talks to the DC) |
| CL |
NS |
SMB2 |
SMB2:C TREE CONNECT (0x3), Path=\\NS\IPC$, Mid = 8 |
| NS |
CL |
SMB2 |
SMB2:R TREE CONNECT (0x3), TID=0x5, Mid = 8 |
| CL |
NS |
DFS |
DFS:Get DFS Referral Request, FileName: \NS\ns1\folder1, MaxReferralLevel: 4 |
| NS |
DC |
ARP |
ARP:Request, 10.1.1.2 asks for 10.1.1.1 |
| DC |
NS |
ARP |
ARP:Request, 10.1.1.1 asks for 10.1.1.2 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49274, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1348431413, Ack=806693705, Win=509 (scale factor 0x8) = 130304 |
| NS |
CL |
DFS |
DFS:Get DFS Referral Response, NumberOfReferrals: 1 VersionNumber: 4 |
| 7.18. CL now knows that it needs to talk to “fs.josebda.local”. Queries DNS to find it’s “10.1.1.3”, then ARP |
| CL |
DC |
DNS |
DNS:QueryId = 0x9848, QUERY (Standard query), Query for FS.josebda.local of type Host Addr on class Internet |
| DC |
CL |
DNS |
DNS:QueryId = 0x9848, QUERY (Standard query), Response - Success, 10.1.1.3 |
| CL |
FS |
ARP |
ARP:Request, 10.1.1.4 asks for 10.1.1.3 |
| FS |
CL |
ARP |
ARP:Response, 10.1.1.3 at 00-15-5D-6C-0D-05 |
| 7.19. CL negotiates a TCP session with FS on port 445 (SMB). Note the ARP back from FS, since it’s the first time it talks to CL |
| CL |
FS |
TCP |
TCP:Flags=......S., SrcPort=49280, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=3441020583, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| FS |
CL |
ARP |
ARP:Request, 10.1.1.3 asks for 10.1.1.4 |
| CL |
FS |
ARP |
ARP:Response, 10.1.1.4 at 00-15-5D-6C-0D-03 |
| FS |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Microsoft-DS(445), DstPort=49280, PayloadLen=0, Seq=109428157, Ack=3441020584, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
FS |
TCP |
TCP:Flags=...A...., SrcPort=49280, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=3441020584, Ack=109428158, Win=513 (scale factor 0x8) = 131328 |
| 7.20. CL negotiates an SMB session with FS(selects SMB2 dialect) |
| CL |
FS |
SMB |
SMB:C; Negotiate, Dialect = PC NETWORK PROGRAM 1.0, LANMAN1.0, Windows for Workgroups 3.1a, LM1.2X002, LANMAN2.1, NT LM 0.12, SMB 2.002 |
| FS |
CL |
SMB2 |
SMB2:R NEGOTIATE (0x0), GUID={8E4F0109-0E04-FD9C-434A-05881428984C}, Mid = 0 |
| 7.21. CL requests a Kerberos service authorization ticket to present to FS.joseba.local for cifs service |
| CL |
DC |
TCP |
TCP:Flags=......S., SrcPort=49281, DstPort=Kerberos(88), PayloadLen=0, Seq=4155214818, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192 |
| DC |
CL |
TCP |
TCP:Flags=...A..S., SrcPort=Kerberos(88), DstPort=49281, PayloadLen=0, Seq=938378401, Ack=4155214819, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49281, DstPort=Kerberos(88), PayloadLen=0, Seq=4155214819, Ack=938378402, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
KerberosV5 |
KerberosV5:TGS Request Realm: JOSEBDA.LOCAL Sname: cifs/FS.josebda.local |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49281, PayloadLen=0, Seq=938378402, Ack=4155216391, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
KerberosV5 |
KerberosV5:TGS Response Cname: Administrator |
| DC |
CL |
TCP |
TCP:[Continuation to #543]Flags=...AP..., SrcPort=Kerberos(88), DstPort=49281, PayloadLen=118, Seq=938379862 - 938379980, Ack=4155216391, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...., SrcPort=49281, DstPort=Kerberos(88), PayloadLen=0, Seq=4155216391, Ack=938379980, Win=513 (scale factor 0x8) = 131328 |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49281, DstPort=Kerberos(88), PayloadLen=0, Seq=4155216391, Ack=938379980, Win=513 (scale factor 0x8) = 131328 |
| 7.22. SMB session with FS is setup. (while the last ACKs for the DC are still coming) |
| CL |
FS |
SMB2 |
SMB2:C SESSION SETUP (0x1), Mid = 1 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Kerberos(88), DstPort=49281, PayloadLen=0, Seq=938379980, Ack=4155216392, Win=513 (scale factor 0x8) = 131328 |
| DC |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Kerberos(88), DstPort=49281, PayloadLen=0, Seq=938379980, Ack=4155216392, Win=0 (scale factor 0x8) = 0 |
| FS |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49280, PayloadLen=0, Seq=109428398, Ack=3441022365, Win=513 (scale factor 0x8) = 131328 |
| FS |
CL |
SMB2 |
SMB2:R SESSION SETUP (0x1) ,SessionFlags=0x0, Mid = 1 |
| 7.23. CL connects to tree \\fs\josebda.local\Share1, opens the folder and file, queries information (note that SMB2 CREATE is also used as “OPEN”) |
| CL |
FS |
SMB2 |
SMB2:C TREE CONNECT (0x3), Path=\\FS.josebda.local\Share1, Mid = 2 |
| FS |
CL |
SMB2 |
SMB2:R TREE CONNECT (0x3), TID=0x1, Mid = 2 |
| CL |
FS |
SMB2 |
SMB2:C CREATE (0x5), Context=DHnQ, Context=MxAc, Context=QFid, Mid = 3 |
| FS |
CL |
SMB2 |
SMB2:R CREATE (0x5), Context=MxAc, Context=QFid, FID=0xFFFFFFFF00000001, Mid = 3 |
| CL |
FS |
SMB2 |
SMB2:C CREATE (0x5), Context=DHnQ, Context=MxAc, Context=QFid, Mid = 4 |
| FS |
CL |
SMB2 |
SMB2:R CREATE (0x5), Context=MxAc, Context=QFid, FID=0xFFFFFFFF00000005, Mid = 4 |
| CL |
FS |
SMB2 |
SMB2:C CLOSE (0x6), FID=0xFFFFFFFF00000001, Mid = 7 |
| FS |
CL |
SMB2 |
SMB2:R CLOSE (0x6), Mid = 7 |
| CL |
FS |
SMB2 |
SMB2:C QUERY INFORMATION (0x10), FID=0xFFFFFFFF00000005, InformationClass=Query FS Volume Info, FID=0xFFFFFFFF00000005, Mid = 8 |
| FS |
CL |
SMB2 |
SMB2:R QUERY INFORMATION (0x10), Mid = 8 |
| CL |
FS |
SMB2 |
SMB2:C QUERY INFORMATION (0x10), FID=0xFFFFFFFF00000005, InformationClass=Query FS Full Size Info, FID=0xFFFFFFFF00000005, Mid = 10 |
| FS |
CL |
SMB2 |
SMB2:R QUERY INFORMATION (0x10), Mid = 10 |
| 7.24. CL disconnects from trees, logs off SMB2 and closes TCP sessions with DC, NS, FS |
| CL |
NS |
TCP |
TCP:Flags=...A...., SrcPort=49278, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1616432609, Ack=802554785, Win=513 (scale factor 0x8) = 131328 |
| CL |
FS |
TCP |
TCP:Flags=...A...., SrcPort=49280, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=3441023554, Ack=109430126, Win=511 (scale factor 0x8) = 130816 |
| CL |
DC |
SMB2 |
SMB2:C TREE DISCONNECT (0x4), TID=0x1, Mid = 5 |
| DC |
CL |
SMB2 |
SMB2:R TREE DISCONNECT (0x4), Mid = 5 |
| CL |
DC |
SMB2 |
SMB2:C LOGOFF (0x2), Mid = 6 |
| DC |
CL |
SMB2 |
SMB2:R LOGOFF (0x2), Mid = 6 |
| CL |
NS |
SMB2 |
SMB2:C TREE DISCONNECT (0x4), TID=0x5, Mid = 10 |
| CL |
DC |
TCP |
TCP:Flags=...A...F, SrcPort=49274, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1348431557, Ack=806693849, Win=508 (scale factor 0x8) = 130048 |
| NS |
CL |
SMB2 |
SMB2:R TREE DISCONNECT (0x4), Mid = 10 |
| DC |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49274, PayloadLen=0, Seq=806693849, Ack=1348431558, Win=511 (scale factor 0x8) = 130816 |
| CL |
NS |
SMB2 |
SMB2:C TREE DISCONNECT (0x4), TID=0x1, Mid = 11 |
| CL |
DC |
TCP |
TCP:[Segment Lost]Flags=...A.R.., SrcPort=49274, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1348431558, Ack=806693849, Win=0 (scale factor 0x8) = 0 |
| NS |
CL |
SMB2 |
SMB2:R TREE DISCONNECT (0x4), Mid = 11 |
| CL |
NS |
SMB2 |
SMB2:C LOGOFF (0x2), Mid = 12 |
| NS |
CL |
SMB2 |
SMB2:R LOGOFF (0x2), Mid = 12 |
| CL |
FS |
SMB2 |
SMB2:C TREE DISCONNECT (0x4), TID=0x1, Mid = 11 |
| CL |
NS |
TCP |
TCP:Flags=...A...F, SrcPort=49278, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1616432825, Ack=802555001, Win=512 (scale factor 0x8) = 131072 |
| NS |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49278, PayloadLen=0, Seq=802555001, Ack=1616432826, Win=507 (scale factor 0x8) = 129792 |
| FS |
CL |
SMB2 |
SMB2:R TREE DISCONNECT (0x4), Mid = 11 |
| CL |
NS |
TCP |
TCP:[Segment Lost]Flags=...A.R.., SrcPort=49278, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=1616432826, Ack=802555001, Win=0 (scale factor 0x8) = 0 |
| NS |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Microsoft-DS(445), DstPort=49278, PayloadLen=0, Seq=802555001, Ack=1616432826, Win=0 |
| CL |
FS |
SMB2 |
SMB2:C LOGOFF (0x2), Mid = 12 |
| FS |
CL |
SMB2 |
SMB2:R LOGOFF (0x2), Mid = 12 |
| CL |
FS |
TCP |
TCP:Flags=...A...F, SrcPort=49280, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=3441023698, Ack=109430270, Win=511 (scale factor 0x8) = 130816 |
| FS |
CL |
TCP |
TCP:Flags=...A...., SrcPort=Microsoft-DS(445), DstPort=49280, PayloadLen=0, Seq=109430270, Ack=3441023699, Win=508 (scale factor 0x8) = 130048 |
| FS |
CL |
TCP |
TCP:Flags=...A.R.., SrcPort=Microsoft-DS(445), DstPort=49280, PayloadLen=0, Seq=109430270, Ack=3441023699, Win=0 (scale factor 0x8) = 0 |