Packet event
The packet event section holds raw networking packets and is used to display
their fields.
Retis parses headers layer by layer, displaying information for each supported protocol as described in the sections below. Depending on how far parsing progresses, the output falls into one of three cases:
-
All headers parsed: the output is fully printed with no trailing indicator.
-
Unsupported protocol encountered: parsing stops at the unsupported layer and the output ends with
... ({protocol} not supported, use 'retis pcap'). There may be interesting data further down the payload that is not shown. -
Truncated or incomplete data: headers are expected but not enough data was available (e.g. due to snap length truncation); parsing stops early and the output ends with
... (truncated or incomplete packet).
Ethernet
{src mac} > {dst mac} ethertype {etype name} ({etype hex})
VLAN
vlan {id} p {prio} [DEI] ethertype {etype name} ({etype hex})
ARP
request who-has {ip} tell {ip}
or,
reply {ip} is at {mac}
IP
For IPv4:
{src ip}.{src port} > {dst ip}.{dst port} tos {tos} {ECN info} ttl {ttl} id {id}
off {frag offset} [{flags}] len {packet len} opts [{IPv4 options}]
proto {protocol name} ({protocol hex})
ECN infocan be one ofCE,ECT(0)orECT(1).flagsare constructed with a combination of+,DFandrsvd.
For IPv6:
{src ip}.{src port} > {dst ip}.{dst port} {ECN info} ttl {ttl} label {flow label}
len {packet len} exts [{IPv6 extensions}] proto {protocol name} ({protocol hex})
TCP
flags [{flags}] seq {sequence} ack {acked sequence} win {window} [{options}]
flagsare constructed using a combination ofF(fin),S(syn),R(reset),P(push),.(ack),U(urgent),E(ece),W(cwr) ande(RFC7560).sequencecan be a range ({start}:{end}) or a single number ({sequence}).- {options} are constructed by listing all options and for some extra information (mss, wscale, sack, echo, echoreply, cc, ccnew, ccecho, timestamp, tfo).
UDP
len {UDP data len}
ICMP & ICMPv6
type {type number} code {code number}
Geneve
geneve [{flags}] vni {vni} proto {etype name} ({etype hex}) [{options}]
flagsare constructed using a combination ofO(control) andC(critical).optionsis a list of options separated by commas of the following form:class {class} type {type} len {len}.typeincludes a trailing "(C)" if the option type has the critical bit set.
If the Netdev GRO hint option is used the above options will contain
additional information of the following form:
(proto {inner proto id} {nested IP version} nh {nested nh offset}
tp {nested tp offset} hlen {nested header len})
VXLAN
vxlan [{flags}] vni {vni}
flagscan beI(set for a valid VNI).
MACsec
an {association number} pn {packet number} [{flags}] sl {short length} sci {sci}
flagsare constructed following the bits set in thetcifield with a combination ofE(encrypted payload),C(changed text),S(end station),B(single copy broadcast) andI(SCI present).
IPsec
ESP
In case a packet has an ESP header, processing of the packet will stop there as the rest is encrypted.
spi {spi} seq {sequence number}
AH
spi {spi} seq {sequence number} icv {icv}
SCTP
vtag {vtag} [{chunk}] [{chunk}] ...
vtagis the verification tag, printed as hex value.- Each chunk is enclosed in
[...]and preceded by a space. Multiple chunks in the same packet are printed sequentially separated by a space. - Some fields in chunks may be skipped depending on packet truncation and Retis snap length.
Chunk types
DATA
[DATA ({flags}) TSN {tsn} SID {sid} SSEQ {sseq} PPID {ppid}]
flagsare constructed using a combination ofU(unordered),B(beginning fragment) andE(ending fragment). The({flags})part is omitted when none of these flags are set.ppidis printed as hex.
INIT
[INIT init_tag {init_tag} rwnd {rwnd} OS {os} MIS {mis} init_TSN {tsn}]
init_tagis printed as hex.
INIT ACK
[INIT ACK init_tag {init_tag} rwnd {rwnd} OS {os} MIS {mis} init_TSN {tsn}]
init_tagis printed as hex.
SACK
[SACK cum_ack {cum_tsn} a_rwnd {a_rwnd} #gap_acks {n_gap} #dup_tsns {n_dup}]
Other known chunks
[HEARTBEAT], [HEARTBEAT_ACK], [ABORT], [SHUTDOWN], [SHUTDOWN_ACK],
[ERROR], [COOKIE_ECHO], [COOKIE_ACK], [ECNE], [CWR],
[SHUTDOWN_COMPLETE].
- No additional fields are included in the above.
Unknown chunk type
[UNKNOWN:{type}]
- Normally, in well formed packets this is never present as this is just a fallback for unknown chunks.
typeis the raw decimal chunk type value.