TCP Handshake
- In Turkish
- TCP el sıkışması
In short
The TCP handshake is the SYN, SYN-ACK, ACK exchange a client and server use to open a connection and agree on starting sequence numbers before sending data.
What is the TCP three-way handshake?
TCP promises reliable, ordered delivery, so both sides must first agree to talk and set up their bookkeeping. The client sends a SYN segment with a random initial sequence number. The server replies with SYN-ACK, acknowledging the client's number and sending its own. The client answers with ACK, and the connection is open.
Sequence numbers are how TCP keeps order: every byte sent is numbered, the receiver acknowledges what it has received, and anything missing is retransmitted. Starting from random values also makes it harder for an attacker to inject forged packets into someone else's connection.
The handshake costs one full round trip before the first byte of data, which is why latency matters so much for web performance. A new HTTPS connection then also needs a TLS handshake, one more round trip with TLS 1.3. Connection reuse, keep-alive, HTTP/2 and QUIC, which combines transport and encryption setup, all reduce these costs.
A common misconception is that closing a connection mirrors the handshake. Closing normally takes four messages, a FIN and an ACK in each direction, because each side finishes sending independently. Also, half-open handshakes can be abused: a SYN flood sends huge numbers of SYNs without completing them, which servers counter with SYN cookies.
Key takeaways
- The handshake is SYN, SYN-ACK, ACK.
- Both sides exchange random initial sequence numbers.
- It costs one round trip before any data flows.
- HTTPS adds a TLS handshake on top; QUIC combines the two.
- Closing uses FIN and ACK in each direction; SYN floods abuse the handshake.
Example
# Capture the start of a connection to example.com on port 443
sudo tcpdump -n 'tcp port 443 and tcp[tcpflags] & (tcp-syn|tcp-ack) != 0' &
curl -s https://example.com -o /dev/null
# Typical output (simplified):
# client > server: Flags [S], seq 1000 ← SYN
# server > client: Flags [S.], seq 5000, ack 1001 ← SYN-ACK
# client > server: Flags [.], ack 5001 ← ACK: connection openReaders ask
Why does TCP need a three-way handshake?
Each side has to send its initial sequence number and get it acknowledged. Three messages are the minimum for both directions to be confirmed: SYN, SYN-ACK carrying the server's number and the acknowledgment, and the final ACK.
Does UDP have a handshake?
No. UDP sends datagrams without setting up a connection, which is why it starts faster but gives no delivery or ordering guarantees. Protocols built on UDP, such as QUIC, add their own handshake.
What is a SYN flood?
A denial-of-service attack that sends many SYN packets without finishing the handshake, filling the server's table of half-open connections. SYN cookies let a server answer without storing state until the handshake completes.
See also
- TCPNetworking, p. 30TCP is a core internet protocol that delivers data between two programs reliably and in order, by opening a connection and resending anything that gets lost.
- UDPNetworking, p. 35UDP is a lightweight internet protocol that sends small, independent messages called datagrams without a connection, favoring speed over guaranteed delivery.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- LatencyNetworking, p. 14Latency is the delay between sending a request and the start of a response, usually measured in milliseconds, and it shapes how responsive an app feels.
- PacketNetworking, p. 20A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
- DDoSSecurity, p. 10A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
Spotted a mistake or something missing on this page?Suggest an edit