Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] MAC address never changes?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: d a <otto81494@xxxxxxxxx>
Date: Mon, 6 Aug 2007 12:01:01 -0700 (PDT)

I used wireshark for Gnuttella traffiic and filtered for a specified IP address. Every capture I make shows the MAC address of the host computer as the same (00:04:de:a3:08:01). I checked the MAC of my NIC and it is correctly shown each time. I dont understand why the traffic from different host computers always comes up as the same MAC. I am certain that these are all different computers. Its my understanding that these should be unique for each NIC. I attached a screen capture and would appreciate an explanation. Note that the destination MACs are identical. The other (source) is my MAC. The red and green filters are for "syn" and Fin" packets.
Thanks
Dave


Moody friends. Drama queens. Your life? Nope! - their life, your story.
Play Sims Stories at Yahoo! Games.

GIF image

  • Follow-Ups:
    • Re: [Wireshark-users] MAC address never changes?
      • From: Luis EG Ontanon
  • Prev by Date: Re: [Wireshark-users] Fw: I am not decode the Nbap and sscop messages.
  • Next by Date: [Wireshark-users] SSL decryption
  • Previous by thread: Re: [Wireshark-users] Fw: I am not decode the Nbap andsscopmessages.
  • Next by thread: Re: [Wireshark-users] MAC address never changes?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation