Unknown frame Src: fe:80:00:00:00:00 Dst: fc:11:20:f1:fc:e8

asked 2018-08-01 17:44:33 +0000

We are having some strange activity on the network, with intermittent slowing down. Wireshark scans produce multiple results from the same source frames are bombarding the network heavily:

Ethernet II, Src: fe:80:00:00:00:00 (fe:80:00:00:00:00), Dst: fc:11:20:f1:fc:e8 (fc:11:20:f1:fc:e8)

frame data shows nothing just same string in every packet and it looks like "T 4 P I" and some garbage.

Any initial thoughts?

This looks like IPv6 with IPv6 Link Local address being dumped onto the network as raw Ethernet. Some kit is malfunctioning for sure.

Jaap gravatar imageJaap ( 2018-08-01 22:09:02 +0000 )edit