трафик вот такой:
Код: Выделить всё
(18:43:24 </>) 0 # tcpdump -i rl0 -vvv host 192.168.1.106
tcpdump: listening on rl0, link-type EN10MB (Ethernet), capture size 96 bytes
18:43:36.380315 IP (tos 0x0, ttl 52, id 9309, offset 0, flags [DF], proto: TCP (6), length: 1466) 510.upl.cz.npp > 192.168.1.106.4916: . 15599294:15600720(1426) ack 4067041062 win 7353
18:43:36.381427 IP (tos 0x0, ttl 128, id 5572, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.106.4916 > 510.upl.cz.npp: ., cksum 0xba1e (correct), 1:1(0) ack 1426 win 65535
18:43:36.472308 IP (tos 0x0, ttl 52, id 9310, offset 0, flags [DF], proto: TCP (6), length: 1466) 510.upl.cz.npp > 192.168.1.106.4916: . 1426:2852(1426) ack 1 win 7353
18:43:36.563290 IP (tos 0x0, ttl 52, id 9311, offset 0, flags [DF], proto: TCP (6), length: 1466) 510.upl.cz.npp > 192.168.1.106.4916: . 2852:4278(1426) ack 1 win 7353
18:43:36.564292 IP (tos 0x0, ttl 128, id 5578, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.106.4916 > 510.upl.cz.npp: ., cksum 0xaefa (correct), 1:1(0) ack 4278 win 65535
18:43:36.655268 IP (tos 0x0, ttl 52, id 9312, offset 0, flags [DF], proto: TCP (6), length: 1466) 510.upl.cz.npp > 192.168.1.106.4916: . 4278:5704(1426) ack 1 win 7353