The correct answer: B
In the first line "Session info: proto=6 proto_state=02"
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2)
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
So this is A to me. Yes, proto_state=02 =SYN_SENT. However, with SYN_SENT, there's no 3-way handshake yet. In this evidence, we see traffic being sent and received, which doesn't work with SYN_SENT. Additionally, the expire timer is 3600s, which is default for ESTABLISHED. SYN_SENT has a default timer of 120s and it makes to sense to increase this.
Looks like a weirdly cobbled together output, but SYN_SENT zooms in on 1 piece of evidence while ignoring everything that contradicts it.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
phototrait
Highly Voted 4 years, 1 month agobrld
Highly Voted 4 years, 1 month agoIbrahimadwan
Most Recent 2 years, 2 months agolearner_88
2 years, 9 months agojohnnd
2 years, 11 months agojmanning
2 years, 11 months agoPascalCert
3 years agoGoshler
3 years agoBluey
3 years ago