We are experiencing sparatic slowness on our network with core/distribution 6509s and 3560, 3750 and 4006 switches at the access layer.
So we put a sniffer on one of the access layer 3560s with no spanning done on the switch and we set up a filter in wire shark to capture wire to show only tcp traffic. I expected to see no traffic as there is no IP address set up on the sniffer pc nic and it is connected to a switchport.
But... that is not the case... I am seeing tcp conversations from one server to another on the capture. All three pc's are in the same vlan/subnet but not on the same switch.
The source pc is in the same switch as the sniffer pc and the destination pc is on a different switch in the same vlan.
Any idea why we would see the conversation at all? Maybe I am just misunderstanding how the switch process works?