Verify if TCP Timestamp has been disabled
hi, instructed tool check if tcp time stamps enabled/disabled on our web servers. using wireshark , nmap. have disabled tcp timestamp on our windows 2012 server. however, in nmap, "uptime guess" can still seen - based on nmap, indication tcp timestamp enabled . in wireshark, not "tcp.options.timestamp.tsval" expression work.
don't know whether scan accurate or server still sending packets tcp timestamp in it. go next? thanks!
hi deos24,
there a key related to timestamp in registry.
check configuration:
tcp1323opts:
https://technet.microsoft.com/en-us/library/cc938205.aspx
the timestamps option field can viewed in network monitor trace expanding tcp options field. check if exists in packets sent server.
timestamps (rfc 1323) :
https://msdn.microsoft.com/en-us/library/aa923592.aspx
here guide network monitor:
https://technet.microsoft.com/en-us/library/cc938655.aspx
best regards,
please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.
Windows Server > Platform Networking
Comments
Post a Comment