# problem with TCP partial connection

**URL:** https://community.zeek.org/t/problem-with-tcp-partial-connection/1134
**Category:** Zeek
**Created:** [February 27, 2007, 10:55am UTC](https://community.zeek.org/t/problem-with-tcp-partial-connection/1134 "2007-02-27T10:55:44Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Bindiya\_V\_S](https://avatars.discourse-cdn.com/v4/letter/b/c89c15/32.png) [@Bindiya\_V\_S](https://community.zeek.org/u/Bindiya_V_S)
#### Post date: [February 27, 2007, 10:55am UTC](https://community.zeek.org/t/problem-with-tcp-partial-connection/1134/1 "2007-02-27T10:55:44Z")

</div>

Hi,

I was trying to use the FTP analyzer in the bro1.2 to analyze  
FTP packets. We were trying to do some tcpreplays with some  
captured pcaps. We have some FTP pcaps that are not having any  
TCP handshake packets. On replaying these packets it is  
observed that the signature matching for TCP is not getting invoked (ie.signatures with ip-proto == tcp).  
It looks like the rulematcher of TCP is not getting called. Is  
there any way we can invoke TCP rulematcher for a set of TCP  
application packets which dont have any handshake packets?

Thanks  
Bindiya

---

<div class="post-metadata">

### Author: ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)
#### Post date: [February 28, 2007, 5:33pm UTC](https://community.zeek.org/t/problem-with-tcp-partial-connection/1134/2 "2007-02-28T17:33:42Z")

</div>

Can you send me one such connection as a pcap trace?

Robin

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)
#### Post date: [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/problem-with-tcp-partial-connection/1134/3 "2022-05-06T15:38:11Z")

</div>


