This toy exchange shows byte counting only, not the rest of TCP behavior.

highlighted = computed this step

What this toy example shows

This book shows one post-handshake data segment and one ACK. It only models byte-counting arithmetic.

payload bytes=2\text{payload bytes}=2
TCP byte-counting boundaryThe toy TCP ACK segment is decoded from exact header bytes.ACK header160 bits / 20 bytes0x01bb9c4000001389000003eb5010100000000000byte 0byte 1byte 2byte 300000001101110111001110001000000byte 4byte 5byte 6byte 700000000000000000001001110001001byte 8byte 9byte 10byte 1100000000000000000000001111101011byte 12byte 13byte 14byte 1501010000000100000001000000000000byte 16byte 17byte 18byte 1900000000000000000000000000000000source-port443destination-port40000sequence-number5001acknowledgment-number1003data-offset5reserved0x0flags0x10window0x1000checksum0x0000urgent-pointer0

Checked values

Client sequence 1001 plus payload length 2 gives ACK 1003.

1001+2=10031001+2=1003
TCP byte-counting boundaryThe toy TCP ACK segment is decoded from exact header bytes.ACK header160 bits / 20 bytes0x01bb9c4000001389000003eb5010100000000000byte 0byte 1byte 2byte 300000001101110111001110001000000byte 4byte 5byte 6byte 700000000000000000001001110001001byte 8byte 9byte 10byte 1100000000000000000000001111101011byte 12byte 13byte 14byte 1501010000000100000001000000000000byte 16byte 17byte 18byte 1900000000000000000000000000000000source-port443destination-port40000sequence-number5001acknowledgment-number1003data-offset5reserved0x0flags0x10window0x1000checksum0x0000urgent-pointer0

What this does not model

NOTE: toy post-handshake byte-counting only; not TCP checksum, retransmission, sliding window, delayed ACKs, segmentation offload, congestion control, or real capture timing.

toy data exchange=1\text{toy data exchange}=1
TCP byte-counting boundaryThe toy TCP ACK segment is decoded from exact header bytes.ACK header160 bits / 20 bytes0x01bb9c4000001389000003eb5010100000000000byte 0byte 1byte 2byte 300000001101110111001110001000000byte 4byte 5byte 6byte 700000000000000000001001110001001byte 8byte 9byte 10byte 1100000000000000000000001111101011byte 12byte 13byte 14byte 1501010000000100000001000000000000byte 16byte 17byte 18byte 1900000000000000000000000000000000source-port443destination-port40000sequence-number5001acknowledgment-number1003data-offset5reserved0x0flags0x10window0x1000checksum0x0000urgent-pointer0

Summary

TCP counts bytes in the stream; this tiny ACK asks for byte 1003 next.

next byte=1003\text{next byte}=1003
TCP byte-counting boundaryThe toy TCP ACK segment is decoded from exact header bytes.ACK header160 bits / 20 bytes0x01bb9c4000001389000003eb5010100000000000byte 0byte 1byte 2byte 300000001101110111001110001000000byte 4byte 5byte 6byte 700000000000000000001001110001001byte 8byte 9byte 10byte 1100000000000000000000001111101011byte 12byte 13byte 14byte 1501010000000100000001000000000000byte 16byte 17byte 18byte 1900000000000000000000000000000000source-port443destination-port40000sequence-number5001acknowledgment-number1003data-offset5reserved0x0flags0x10window0x1000checksum0x0000urgent-pointer0