Ask Your Question

Revision history [back]

Missing MAC addresses in pcap.

Recently all of my clients have been sending pcaps that appear to be missing MAC addresses. I'll have 10 MAC and 100 IPs. At first I thought maybe this was a user error at the time of collection and they were filtering out Layer 2, but it's started happening all of the sudden, among different clients, using different switch vendors.

I am starting to wonder if a new Wireshark update might have changed some default capture settings. Has anyone else experienced this?