No matter where I plug into, I see one-to-one traffic (host-to-host) not broadcasts. It seems like there is a switch or router broadcasting this traffic. Please point me in a better direction I cant come up with any other ideas.
check MAC addresses in the frames. Aren't they multicasts or somehow strange? Maybe the hosts are using some special application to communicate (Symantec Ghost, PGP, e.g.)?
It could be unicast flooding. There are several possible reasons for this, so search Cisco.com for the term.
Which Sniffer software are you using ?
If you are using the Microsoft's Free Network Monitor.. it can only monitor one - one traffic..
just like a switch based network.. but if you sniff with the full version you will get the full prmoiscious capability..
I encountered the same Problem. I've got sniffer pro too, and with a c3550G-48 12.1(11)EA1, I had the same pbm. I moved to IOS 12.1(12c)EA1 And I have no longer unicast frames. It was not flooding because there was only a few unicast frames arriving on my port