Verify if TCP Timestamp has been disabled


hi, instructed tool check if tcp time stamps enabled/disabled on our web servers. using wireshark , nmap. have disabled tcp timestamp on our windows 2012 server. however, in nmap, "uptime guess" can still seen - based on nmap, indication tcp timestamp enabled . in wireshark, not "tcp.options.timestamp.tsval" expression work. 

don't know whether scan accurate or server still sending packets tcp timestamp in it. go next? thanks!


hi deos24,

there a key related to timestamp in registry.

check configuration:
tcp1323opts:
https://technet.microsoft.com/en-us/library/cc938205.aspx

the timestamps option field can viewed in network monitor trace expanding tcp options field. check if exists in packets sent server.

timestamps (rfc 1323) :
https://msdn.microsoft.com/en-us/library/aa923592.aspx

here guide network monitor:
https://technet.microsoft.com/en-us/library/cc938655.aspx

best regards,

leo


please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Platform Networking



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...