The correct answer: B
In the first line "Session info: proto=6 proto_state=02"
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2)
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
So this is A to me. Yes, proto_state=02 =SYN_SENT. However, with SYN_SENT, there's no 3-way handshake yet. In this evidence, we see traffic being sent and received, which doesn't work with SYN_SENT. Additionally, the expire timer is 3600s, which is default for ESTABLISHED. SYN_SENT has a default timer of 120s and it makes to sense to increase this.
Looks like a weirdly cobbled together output, but SYN_SENT zooms in on 1 piece of evidence while ignoring everything that contradicts it.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
phototrait
Highly Voted 3 years, 10 months agobrld
Highly Voted 3 years, 10 months agoIbrahimadwan
Most Recent 1 year, 11 months agolearner_88
2 years, 6 months agojohnnd
2 years, 8 months agojmanning
2 years, 8 months agoPascalCert
2 years, 9 months agoGoshler
2 years, 9 months agoBluey
2 years, 10 months ago