Not sure if this helps, but I ran tcpdump -i eth107 -nnn host 00.00.00.00 and port 1099 from dreamcast01.loc.domain.com (the jmx server) to the splunksearch02.loc.domain.com and see the following:
13:13:26.299948 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [S], seq 1540665743, win 29200, options [mss 1460,sackOK,TS val 3664785512 ecr 0,nop,wscale 7], length 0
13:13:26.300336 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [.], ack 1, win 229, options [nop,nop,TS val 3664785512 ecr 466171144], length 0
13:13:26.300362 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [P.], seq 1:8, ack 1, win 229, options [nop,nop,TS val 3664785512 ecr 466171144], length 7
13:13:26.300995 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [.], ack 19, win 229, options [nop,nop,TS val 3664785512 ecr 466171144], length 0
13:13:26.301085 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [P.], seq 8:25, ack 19, win 229, options [nop,nop,TS val 3664785512 ecr 466171144], length 17
13:13:26.301218 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [P.], seq 25:75, ack 19, win 229, options [nop,nop,TS val 3664785512 ecr 466171144], length 50
13:13:26.305359 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [P.], seq 75:90, ack 246, win 237, options [nop,nop,TS val 3664785513 ecr 466171144], length 15
13:13:56.303081 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [F.], seq 90, ack 246, win 237, options [nop,nop,TS val 3664793013 ecr 466171155], length 0
13:13:56.303453 IP 00.00.00.00.56756 > 00.00.00.00.1099: Flags [.], ack 247, win 237, options [nop,nop,TS val 3664793013 ecr 466178645], length 0
... View more