ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-users: Re: [Ethereal-users] MS-based Ethertype Decode

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "M.C. van den Bovenkamp" <marco@xxxxxxxxxxxxxxxxxxx>
Date: Fri, 01 Feb 2002 18:33:03 +0100
Scott Fringer wrote:

>   I'm seeing a good deal (from one host) of traffic of Ethertype x886f
> sourced from MAC address 02:01:00:00:00:00 destined to the local

That's MS Network Load Balancing heartbeat.

> site turn up no information on this Ethertype or MAC address.

But a Google search would have; see for instance
http://archives.neohapsis.com/archives/incidents/2000-12/0095.html

> The user
> of the system is not aware of anything 'enabled' on his Win2000 system
> that could be generating this traffic.

Look for the above.

		Regards,

			Marco.