Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] eth.fcs==0x00000000

From: Stuart Kendrick <skendric@xxxxxxxxx>
Date: Sat, 24 Nov 2012 13:27:00 -0800
I'm seeing ARP Requests and Responses with the Ethernet Frame check
sequence set to all zeros .... the expert layer flags these as 'Ethernet
Frame Check Sequence Incorrect'

Tentatively, all the emitters of these ARPs are Windows guests on a
VMWare cluster ...

I captured all ARPs in this particular data center for an hour+ ...
~307,000 ... of which 1100 have an Ethernet FCS of 0x00000000

I've focused on a handful of these ... for one of these VMs (an AD
domain controller), /every single ARP/ which it emits sports an FCS of
0x00000000
For the other handful on which I've filtered, they are mixed:  in some
cases, just a few such ARPs, in other cases mostly but not all.

Anyone recognize this?

--sk

Stuart Kendrick
FHCRC