Using the decoder
Paste the bytes of a packet as hex. Plain hex, spaced bytes and colon-separated bytes all work, and so does a hex dump copied from Wireshark or tcpdump, offsets and ASCII column included. If the bytes start with an Ethernet header carrying IPv4, it's read and skipped.
You get every IPv4 field and, for TCP, every TCP field: ports with their usual services, sequence and acknowledgement numbers, the flags, window and options. Both checksums are verified, and Show the steps draws the IPv4 header row by row. For a TCP header on its own, set Starts with to TCP.
Nothing you paste leaves your browser, so it's safe to decode a capture from a private network here.
The IPv4 header
The header is at least 20 bytes, laid out in 32-bit rows. The first byte holds two numbers. The high four bits are the version, 4, and the low four are the header length in 32-bit words, normally 5. That's why almost every IPv4 packet begins 45.
Then come the total length of the packet, the fragmentation fields (Don't fragment is usually set), the TTL each router lowers by one, the protocol of what follows (6 is TCP, 17 UDP, 1 ICMP), the header checksum, and the source and destination addresses.
The TCP header and its flags
TCP starts where the IPv4 header ends: two ports, a sequence number, an acknowledgement number, the header length, eight flags, the window, a checksum, the urgent pointer, and up to 40 bytes of options.
The flags are one byte, from CWR on the left to FIN on the right. A connection opens with the three-way handshake. The client sends SYN, the server answers SYN and ACK, and the client sends ACK. FIN closes a direction politely and RST aborts the connection. The sample in the box is a SYN, with the options a Linux client sends: maximum segment size, SACK permitted, timestamps and window scale.
A checksum every router redoes
The IPv4 checksum covers only the header, and the header changes at every hop because the TTL goes down by one. So every router that forwards a packet has to recompute the checksum. IPv6 dropped the header checksum altogether and left error checking to the link below and the transport above.
If a capture shows a TCP checksum as wrong, it often isn't. Many network cards fill the checksum in after the capture point, so the copy in the capture still holds whatever was there before.
Questions
Why does every IPv4 packet start with 45?
The 4 is the version and the 5 is the header length in 32-bit words: 20 bytes, the size with no options.
How is the IPv4 checksum calculated?
Add the header as 16-bit words with the checksum field set to zero, fold any carry back into the low 16 bits, and invert. Checking it over the whole header, checksum included, gives zero when it's intact.
What do the TCP flags mean?
SYN opens a connection, ACK acknowledges data, FIN closes one direction, RST aborts, PSH asks for prompt delivery, URG marks urgent data, and ECE and CWR handle congestion signals.
Can I paste a Wireshark hex dump?
Yes. Copy the bytes as a hex dump; the offsets and the ASCII column are ignored.
Sources
- RFC 791: Internet Protocol
- RFC 9293: Transmission Control Protocol
- RFC 1071: Computing the Internet Checksum
- Wikipedia: Internet checksum
Added . What's new






