Wireshark

  • Riverbed Technology
  • WinPcap
SHARKFEST '12 - Wireshark Developer and User Conference - June 24-27, 2012 - UC Berkeley, Clark Kerr Campus
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Is this normal?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Tue, 31 Mar 2009 13:16:34 -0600

On Tue, Mar 31, 2009 at 12:59:26PM -0400, Peter Hartmann wrote:

> I also see quite a bit of this kind of thing.  From what I understand, 
> this address 239.255.1.1 falls in a range dedicated to multicast.  
> I'm also wondering if the spanning tree packets mean that there is a 
> cable plugged in to a switch twice.  Could that be?
> 
> 54 7.619442 10.3.85.127 239.255.1.1 UDP Source port: dnox Destination 
> port: dnox

Yes, this is a muliticast in the range that is "locally administered."  
Maybe this is an audio and/or video broadcast that just happens to use 
port 4022 (dnox)?

> 57 8.000269 Netgear_de:9b:97 Spanning-tree-(for-bridges)_00 STP Conf. 
> Root = 32768/00:0f:b5:de:9b:97 Cost = 0 Port = 0x8001

This is not indicative of anything out of the ordinary.


Steve


  • References:
    • [Wireshark-users] Is this normal?
      • From: Peter Hartmann
  • Prev by Date: [Wireshark-users] Comparing Ingress and Egress PCAPs - How?
  • Previous by thread: Re: [Wireshark-users] Is this normal?
  • Next by thread: [Wireshark-users] Comparing Ingress and Egress PCAPs - How?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation