Part 3 · 2 chapters · ~12 min
TCP in Depth
The TCP header, the three-way handshake and its cost, sequence and acknowledgement numbers, retransmission timeouts and fast retransmit, selective acknowledgement, flow control and window scaling, Nagle and delayed ACKs, connection states including TIME_WAIT and CLOSE_WAIT, and keep-alive.
6
Handshake, bytes and close
code
ss -tin dst 10.0.4.7 # per-connection: rtt, rto, cwnd, retrans, send and receive windows
netstat -an | awk '/tcp/ {print $6}' | sort | uniq -c # connection states on this hostTCP: HANDSHAKE, DATA, CLOSE
sequence numbers make an unreliable network look like a reliable stream
swipe the figure sideways, or tap expand for full screen
1/4
three-way handshake
SYN, SYN-ACK, ACK agree on initial sequence numbers (random, to resist spoofing) and options (window scaling, MSS, SACK). It costs one round trip before data can flow.
one round trip before datarandom ISNs, options negotiated
7
Retransmission, Nagle and keep-alive
| mechanism | what it does | production effect |
|---|---|---|
| retransmission timeout (RTO) | resend if no ACK within an estimate based on measured RTT (minimum ~200 ms on Linux) | one lost packet on an idle connection can add hundreds of ms |
| fast retransmit | three duplicate ACKs trigger an immediate resend | recovers quickly when data keeps flowing |
| SACK | receiver reports exactly which ranges arrived | only missing pieces are resent |
| Nagle's algorithm | delays small writes until an ACK arrives, to coalesce them | combined with delayed ACKs, adds ~40-200 ms to request-response protocols; most servers set TCP_NODELAY |
| keep-alive probes | detect dead peers on idle connections | OS defaults are hours; applications and LBs use their own idle timeouts |