cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
692
Views
0
Helpful
10
Replies

Traffic I shouldn't see in a Sniffer trace????

A11055
Level 1
Level 1

No matter where I plug into, I see one-to-one traffic (host-to-host) not broadcasts. It seems like there is a switch or router broadcasting this traffic. Please point me in a better direction I can’t come up with any other ideas.

10 Replies 10

brocknathan
Level 4
Level 4

Who are the hosts on the network that are implementing this one-to-one traffic?

real world address -> workstation

The traffic is oneway. I don't see the workstation talking back

milan.kulik
Level 10
Level 10

Hi,

check MAC addresses in the frames. Aren't they multicasts or somehow strange? Maybe the hosts are using some special application to communicate (Symantec Ghost, PGP, e.g.)?

Regards,

Milan

The MAC's are not multicast or broadcasts. How would an application produce this traffic?

ahojmark
Level 1
Level 1

It could be unicast flooding. There are several possible reasons for this, so search Cisco.com for the term.

-A

Asbjoern Hoejmark | CTO | CCIE #8525
Wingmen Solutions A/S | Gyngemose Parkvej 50, 1. | DK-2860 Søborg | Denmark
M: +4525162108 | E: ah@wingmen.dk | W: www.wingmen.dk

What type of device are you plugging into?

2950

rpgccie
Level 1
Level 1

Which Sniffer software are you using ?

If you are using the Microsoft's Free Network Monitor.. it can only monitor one - one traffic..

just like a switch based network.. but if you sniff with the full version you will get the full prmoiscious capability..

NAI - SNIFFER PRO

I encountered the same Problem. I've got sniffer pro too, and with a c3550G-48 12.1(11)EA1, I had the same pbm. I moved to IOS 12.1(12c)EA1 And I have no longer unicast frames. It was not flooding because there was only a few unicast frames arriving on my port