In a TCP header, what do the SYN, ACK, FIN, RST, PSH and URG control flags each signal?
answer
- one bit each, several per segment
- sequence setup versus field validity
- orderly finish versus abort
- push is not a message boundary
- urgent pointer, now discouraged
basics
~20 sSYN synchronizes sequence numbers to open a connection, ACK says the acknowledgment field is valid, FIN means the sender has no more data, RST aborts the connection, PSH asks for prompt delivery, and URG marks the urgent pointer as significant.
solid answer
~40 sThe flags are single bits in the TCP header, and one segment can carry several of them. `SYN` synchronizes sequence numbers: its sequence number is the initial sequence number, so it opens a connection. `ACK` says the acknowledgment number field is meaningful, and once a connection is established it is always set. `FIN` means the sender has no more data to send, an orderly close of its direction, while `RST` resets the connection outright. `PSH` asks the sending TCP to transmit buffered data promptly; RFC 9293 states that it is not a record marker. `URG` says the urgent pointer field is significant, a mechanism RFC 6093 tells new applications not to use. RFC 9293 also lists `CWR` and `ECE`, which RFC 3168 added for Explicit Congestion Notification.
go deeper
Recall the six flags by name and one sentence each, and be able to say which combination opens a connection and which two ways a connection can end.
Explain why nearly every segment carries ACK, why SYN and FIN consume sequence numbers while RST does not, and why PSH gives the receiver no message boundaries.
Read an unfamiliar flag combination in a capture and say what state each side must be in, including resets for non-existent connections and ECN-setup SYNs.
Be ready to explain why the urgent mechanism was effectively retired and what that says about protocol features whose semantics implementations interpreted differently.
## Where the flags sit in the header A TCP header starts with 20 fixed bytes. In the fourth 32-bit word, after the 4-bit **Data Offset** and the 4-bit **Reserved** field, come eight one-bit **control bits**, which RFC 9293 says "are also known as flags". In order they are `CWR`, `ECE`, `URG`, `ACK`, `PSH`, `RST`, `SYN` and `FIN`. The first two were carved out of what used to be reserved space by RFC 3168 (Explicit Congestion Notification); the other six are the ones every interview means by "the TCP flags". Each flag is independent. A segment can set none, one or several, and reading a capture is mostly a matter of reading the combination. ## The six classic flags | Flag | Name in RFC 9293 | What it tells the receiver | |---|---|---| | `SYN` | Synchronize sequence numbers | The sequence number field holds the **initial sequence number**; the first data byte will be ISN+1 | | `ACK` | Acknowledgment field is significant | The acknowledgment number is the next sequence number this sender expects to receive | | `FIN` | No more data from sender | This direction of the byte stream is finished; the peer may still send | | `RST` | Reset the connection | Abandon the connection state now | | `PSH` | Push function | The sender asked for this data to be transmitted promptly | | `URG` | Urgent pointer field is significant | Read the urgent pointer, which marks where urgent data ends | Two details from the table matter more than they look: - **`ACK` is not a "pure acknowledgment" marker.** After the handshake, RFC 9293 says the acknowledgment field is always sent, so almost every segment, including every data segment, has `ACK` set. Only the very first `SYN` of a connection normally lacks it. - **`SYN` and `FIN` occupy sequence space.** RFC 9293 calls them the only controls that need it, which is why a `FIN` is acknowledged like a byte of data. `RST` is not one of them: it consumes no sequence space and is never answered with another reset. ## Common combinations Reading flags in a capture is pattern recognition: 1. `SYN` alone: the first segment of an active open. 2. `SYN` + `ACK`: the reply that accepts it and sends the responder's own initial sequence number. 3. `ACK` alone, no payload: a pure acknowledgment or a window update. 4. `ACK` + `PSH` with payload: ordinary data, the last segment of whatever the sender had buffered. 5. `FIN` + `ACK`: one side has finished sending. 6. `RST`, often with `ACK`: an abort, or a reply to a segment for a connection that does not exist. The handshake and the full close sequence are separate topics; here the point is only what each bit asserts. ## FIN versus RST `FIN` is **graceful**. It is sequenced, it arrives after all the data sent before it, it is acknowledged, and it closes only one direction; the other side can keep sending until it sends its own `FIN`. `RST` is **abortive**. RFC 9293 sends a reset, for example, in answer to any segment (other than another reset) that arrives for a connection that does not exist, which is what a client sees as "connection refused" when nothing listens on a port. Data still in flight when a reset arrives is not delivered. ## PSH and URG: the two most misunderstood flags - **`PSH` is not a message boundary.** RFC 9293 says plainly: "The PSH bit is not a record marker and is independent of segment boundaries." A sending TCP sets it on the last segment it builds from a buffer, and it SHOULD collapse successive pushes into the largest possible segment. A receiver MAY pass it up to the application but is not required to. Applications that need messages must frame them themselves, with a length prefix or a delimiter. - **`URG` is not out-of-band data.** RFC 6093 states that "The TCP urgent mechanism is NOT a mechanism for sending 'out-of-band' data": urgent data is part of the ordinary byte stream, and the 16-bit **urgent pointer** marks the octet following it. Implementations historically disagreed on the pointer's meaning, so RFC 6093 and RFC 9293 both say **new applications SHOULD NOT use it**, while stacks MUST still support it for old ones. ## CWR and ECE in one line each `ECE` (ECN-Echo) and `CWR` (Congestion Window Reduced) let a receiver report a router's congestion mark and let the sender confirm it reacted. In a `SYN` they have a special reading: RFC 3168 calls a `SYN` with both set an **ECN-setup SYN**, and a `SYN-ACK` with only `ECE` set an ECN-setup `SYN-ACK`. What the sender does about congestion is a separate subject. ## How to answer in an interview - Name the bit and the field or behaviour it governs, not just the English word. - Say that flags combine, and give `SYN`+`ACK` as the example. - Contrast `FIN` and `RST` in one sentence each. - Pre-empt the two classic mistakes: `PSH` is not a message boundary and `URG` is not a side channel.
- Why does TCP need both a FIN flag and an RST flag rather than one way to close?They serve different endings. `FIN` is part of the byte stream: it is sequenced after all earlier data, acknowledged, and closes only the sender's direction, so nothing is lost. `RST` abandons the connection at once and consumes no sequence number; it is how TCP rejects a segment for a connection that does not exist, for instance a connection attempt to a port with no listener, and how a side aborts when it cannot continue.
- In a TCP capture, how do the ECE and CWR flags on a SYN differ from the same flags later in the connection?On a `SYN`, RFC 3168 gives them a setup meaning: `SYN` with both `ECE` and `CWR` set is an ECN-setup SYN offering Explicit Congestion Notification, and a `SYN-ACK` with only `ECE` set accepts it. Later in the connection `ECE` echoes a congestion mark back to the sender and `CWR` tells the receiver the sender has reduced its congestion window.
saying these in an interview costs you the question
- PSH marks the end of an application message for the receiver
- RST is just a faster close and all sent data still arrives
- The ACK flag is set only on segments that carry no data
- URG opens a separate out-of-band channel for urgent bytes
- A TCP segment can carry only one flag at a time