Part 3 · 2 chapters · ~12 min

TCP in Depth

The TCP header, the three-way handshake and its cost, sequence and acknowledgement numbers, retransmission timeouts and fast retransmit, selective acknowledgement, flow control and window scaling, Nagle and delayed ACKs, connection states including TIME_WAIT and CLOSE_WAIT, and keep-alive.

6

Handshake, bytes and close

code
ss -tin dst 10.0.4.7      # per-connection: rtt, rto, cwnd, retrans, send and receive windows
netstat -an | awk '/tcp/ {print $6}' | sort | uniq -c   # connection states on this host
TCP: HANDSHAKE, DATA, CLOSE
sequence numbers make an unreliable network look like a reliable stream
clientserverSYN seq=1000SYN-ACK seq=5000 ack=1001ACK ack=5001 (+ data)
swipe the figure sideways, or tap expand for full screen
1/4
three-way handshake
SYN, SYN-ACK, ACK agree on initial sequence numbers (random, to resist spoofing) and options (window scaling, MSS, SACK). It costs one round trip before data can flow.
one round trip before datarandom ISNs, options negotiated
7

Retransmission, Nagle and keep-alive

mechanismwhat it doesproduction effect
retransmission timeout (RTO)resend if no ACK within an estimate based on measured RTT (minimum ~200 ms on Linux)one lost packet on an idle connection can add hundreds of ms
fast retransmitthree duplicate ACKs trigger an immediate resendrecovers quickly when data keeps flowing
SACKreceiver reports exactly which ranges arrivedonly missing pieces are resent
Nagle's algorithmdelays small writes until an ACK arrives, to coalesce themcombined with delayed ACKs, adds ~40-200 ms to request-response protocols; most servers set TCP_NODELAY
keep-alive probesdetect dead peers on idle connectionsOS defaults are hours; applications and LBs use their own idle timeouts