Snif your telnet action also (including connection and disconnection) and compare the captures. Wireshark shows you, up to the bit level, what the exchanges are.