Frame 70: 74 bytes on wire (592 bits), 74 bytes captured (592 bits) Encapsulation type: Ethernet (1) Arrival Time: Feb 17, 2022 03:46:07.586047000 Hora oficial do Brasil [Time shift for this packet: 0.000000000 seconds] Epoch Time: 1645080367.586047000 seconds [Time delta from previous captured frame: 0.005240000 seconds] [Time delta from previous displayed frame: 0.005240000 seconds] [Time since reference or first frame: 2.178101000 seconds] Frame Number: 70 Frame Length: 74 bytes (592 bits) Capture Length: 74 bytes (592 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp] [Coloring Rule Name: Bad TCP] [Coloring Rule String: tcp.analysis.flags && !tcp.analysis.window_update && !tcp.analysis.keep_alive && !tcp.analysis.keep_alive_ack]Ethernet II, Src: 86:00:00:c5:5b:c3 (86:00:00:c5:5b:c3), Dst: 86:00:00:ba:44:a8 (86:00:00:ba:44:a8) Destination: 86:00:00:ba:44:a8 (86:00:00:ba:44:a8) Address: 86:00:00:ba:44:a8 (86:00:00:ba:44:a8) .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Source: 86:00:00:c5:5b:c3 (86:00:00:c5:5b:c3) Address: 86:00:00:c5:5b:c3 (86:00:00:c5:5b:c3) .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Type: IPv4 (0x0800)Internet Protocol Version 4, Src: 10.0.0.4, Dst: 163.181.56.154 0100 .... = Version: 4 .... 0101 = Header Length: 20 bytes (5) Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT) 0000 00.. = Differentiated Services Codepoint: Default (0) .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0) Total Length: 60 Identification: 0x7d94 (32148) Flags: 0x40, Don't fragment 0... .... = Reserved bit: Not set .1.. .... = Don't fragment: Set ..0. .... = More fragments: Not set ...0 0000 0000 0000 = Fragment Offset: 0 Time to Live: 63 Protocol: TCP (6) Header Checksum: 0xd7d4 [validation disabled] [Header checksum status: Unverified] Source Address: 10.0.0.4 Destination Address: 163.181.56.154Transmission Control Protocol, Src Port: 59868, Dst Port: 443, Seq: 0, Len: 0 Source Port: 59868 Destination Port: 443 [Stream index: 4] [Conversation completeness: Incomplete, SYN_SENT (1)] [TCP Segment Len: 0] Sequence Number: 0 (relative sequence number) Sequence Number (raw): 1180875598 [Next Sequence Number: 1 (relative sequence number)] Acknowledgment Number: 0 Acknowledgment number (raw): 0 1010 .... = Header Length: 40 bytes (10) Flags: 0x002 (SYN) 000. .... .... = Reserved: Not set ...0 .... .... = Nonce: Not set .... 0... .... = Congestion Window Reduced (CWR): Not set .... .0.. .... = ECN-Echo: Not set .... ..0. .... = Urgent: Not set .... ...0 .... = Acknowledgment: Not set .... .... 0... = Push: Not set .... .... .0.. = Reset: Not set .... .... ..1. = Syn: Set [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 443] [Connection establish request (SYN): server port 443] [Severity level: Chat] [Group: Sequence] .... .... ...0 = Fin: Not set [TCP Flags: ··········S·] Window: 64860 [Calculated window size: 64860] Checksum: 0xee2f [unverified] [Checksum Status: Unverified] Urgent Pointer: 0 Options: (20 bytes), Maximum segment size, SACK permitted, Timestamps, No-Operation (NOP), Window scale TCP Option - Maximum segment size: 1410 bytes Kind: Maximum Segment Size (2) Length: 4 MSS Value: 1410 TCP Option - SACK permitted Kind: SACK Permitted (4) Length: 2 TCP Option - Timestamps: TSval 1877874971, TSecr 0 Kind: Time Stamp Option (8) Length: 10 Timestamp value: 1877874971 Timestamp echo reply: 0 TCP Option - No-Operation (NOP) Kind: No-Operation (1) TCP Option - Window scale: 7 (multiply by 128) Kind: Window Scale (3) Length: 3 Shift count: 7 [Multiplier: 128] [Timestamps] [Time since first frame in this TCP stream: 1.010634000 seconds] [Time since previous frame in this TCP stream: 1.010634000 seconds] [SEQ/ACK analysis] [TCP Analysis Flags] [Expert Info (Note/Sequence): A new tcp session is started with the same ports as an earlier session in this trace] [A new tcp session is started with the same ports as an earlier session in this trace] [Severity level: Note] [Group: Sequence] [Expert Info (Note/Sequence): This frame is a (suspected) retransmission] [This frame is a (suspected) retransmission] [Severity level: Note] [Group: Sequence] [The RTO for this segment was: 1.010634000 seconds] [RTO based on delta from frame: 61]
about Presto: a single host (Ubuntu Server 20.04) isolated for tests (10.0.0.4).
what problems might we have by disabling state tracking in this or other rules?
is the resolution to problem above the highlighted item?