On Tue, 22 Aug 2017 20:10:39 +0000 (UTC), Bram van den Heuvel
wrote:
All good questions. Here is a Wireshark screenshot from when I first
noticed the *outgoing* IP address 104.28.17.56 from my desktop 192.168.1.99
via my router 192.168.1.1 as shown in this screenshot
I didn't stare long at your packet captures, but from what I saw, I
couldn't tell which end initiated the connection. Since it's a TCP
connection, it'll start with a SYN, then a SYN,ACK in return, and a
final ACK. Once the three-way-handshake is successful and complete, the
actual data transfer can start. The first SYN comes from the side that
wants to initiate the connection.
You can use the filter capability above Wireshark's display area to
enter filter terms, or just right click on something interesting and
tell it to "Apply as Filter". That really cleans up the display.
http://img4.imagetitan.com/img.php?i...nshot(603).jpg
My ancient newsreader initially wanted to render that link as
http://img4.imagetitan.com/img.php?image=16_screenshot
and I was going to ask "What language is that??"