Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] 78 percent of ARP packets on the network

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

Date: Wed, 26 May 2004 15:40:43 -0500
My network started to slow down a few days ago. So I installed latest ethereal
and winpcap for windows in a NT Server 4.0. All the network is switched and I
was trying to find some cause of slowdown. I am aware of the limitations of
sniffing on a switched network so I set the switches to replicate traffic so i
can see it with ethereal.
So far so good, but in the main ethereal windows where it shows how many packets
per protocol has received during the sniffing session I found that after 1 hour
of sniffing 78% of my traffic was ARP and the rest was TCP(normal smb, tns,
etc).

All the network has windows machines (95,98,NT,2000,XP) all servers are NT 4.0
and the network has one PDC one BDC and one WINS server.

I did a search on the mailing list but found no clue about it. Maybe this is
normal but I just dont know.

Comments/Flames/Suggestions are welcomed.

Erick.