Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 7247] New: IPX Traffic Mac Addresses

Date: Fri, 11 May 2012 05:10:57 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7247

           Summary: IPX Traffic Mac Addresses
           Product: Wireshark
           Version: 1.6.2
          Platform: x86
        OS/Version: Ubuntu
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: bugzilla-admin@xxxxxxxxxxxxx
        ReportedBy: jjalbert@xxxxxxxxx


Created attachment 8412
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=8412
Picture of Packet

Build Information:
Version 1.6.2

Copyright 1998-2011 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (32-bit) with GTK+ 2.24.6, with GLib 2.29.92, with libpcap 1.1.1, with
libz 1.2.3.4, with POSIX capabilities (Linux), without libpcre, with SMI 0.4.8,
with c-ares 1.7.4, with Lua 5.1, without Python, with GnuTLS 2.10.5, with
Gcrypt
1.5.0, with MIT Kerberos, with GeoIP, with PortAudio V19-devel (built Jul 27
2011 11:30:44), without AirPcap.

Running on Linux 3.0.0-19-generic, with libpcap version 1.1.1, with libz
1.2.3.4, GnuTLS 2.10.5, Gcrypt 1.5.0.

Built using gcc 4.6.1.

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information
_______________________________________________________________________________

TShark 1.4.6

Copyright 1998-2011 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (32-bit) with GLib 2.28.6, with libpcap 1.1.1, with libz 1.2.3.4, with
POSIX capabilities (Linux), without libpcre, with SMI 0.4.8, with c-ares 1.7.3,
with Lua 5.1, without Python, with GnuTLS 2.8.6, with Gcrypt 1.4.6, with MIT
Kerberos, with GeoIP.

Running on Linux 2.6.38-8-generic-pae, with libpcap version 1.1.1, with libz
1.2.3.4.

Built using gcc 4.5.2.


--
I am using tshark 1.4.6 on an Ubuntu server to capture traffic on my network.
Once the traffic is captured, I transfer the -w file output to my workstation,
where I then import it to Wireshark version 1.6.2. The issue I have noticed is
that if I do a capture on a single interface, everything looks normal, If i do
a capture using -i any I get a pile of IPX traffic, in which the source in the
Linux Cooked Capture may or may not have a mac address that is a device
registered to my network, but in the Internetwork Packet Exchange, neither the
source or destination mac addresses are registered to my network. They are BOTH
machines that I do not have in my network at all. I posted this question on a
fourm, and they suggested that I open a bug report to see if it was an issue in
Wireshark.

Thanks you for you Time and Help.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.