by stefan » Jan 15 08 3:41 pm
Here is a log file from a wireshark protocol analizer where 10.10.10.3 is the proxy and 10.10.10.72 is the client . Destination is port 995 gmail pop server.
Hope this may help. T
ime Source Destination Protocol Info
3436 40.306498 10.10.10.72 gmail-pop.l.google.com TCP bmc-ar > pop3s [SYN] Seq=0 Win=65535 Len=0 MSS=1460
Frame 3436 (62 bytes on wire, 62 bytes captured)
Arrival Time: Jan 14, 2008 20:27:30.927482000
[Time delta from previous captured frame: 0.085311000 seconds]
[Time delta from previous displayed frame: 0.085311000 seconds]
[Time since reference or first frame: 40.306498000 seconds]
Frame Number: 3436
Frame Length: 62 bytes
Capture Length: 62 bytes
[Frame is marked: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Foxconn_d9:b7:ee (00:15:58:d9:b7:ee), Dst: 10.10.10.3 (00:0d:56:fe:3d:a2)
Destination: 10.10.10.3 (00:0d:56:fe:3d:a2)
Source: Foxconn_d9:b7:ee (00:15:58:d9:b7:ee)
Type: IP (0x0800)
Internet Protocol, Src: 10.10.10.72 (10.10.10.72), Dst: gmail-pop.l.google.com (64.233.163.109)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
Total Length: 48
Identification: 0xc058 (49240)
Flags: 0x04 (Don't Fragment)
Fragment offset: 0
Time to live: 128
Protocol: TCP (0x06)
Header checksum: 0x41c7 [correct]
Source: 10.10.10.72 (10.10.10.72)
Destination: gmail-pop.l.google.com (64.233.163.109)
Transmission Control Protocol, Src Port: bmc-ar (2494), Dst Port: pop3s (995), Seq: 0, Len: 0
Source port: bmc-ar (2494)
Destination port: pop3s (995)
Sequence number: 0 (relative sequence number)
Header length: 28 bytes
Flags: 0x02 (SYN)
Window size: 65535
Checksum: 0xd44c [correct]
Options: (8 bytes)