This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Why i receive packets these packets ? ( no mirror port configured )

0

Hi,

I'm running Wireshark on server to see packets from / to this server, but something strange that i see conversations between other sources & destinations, this server is not part of these conversations i'm sure that there is no mirror port to this server so i'm wondering ?!!

Any help ?

asked 11 Aug '15, 23:26

Mahmoud%20Saad's gravatar image

Mahmoud Saad
1111
accept rate: 0%


One Answer:

1

If you're seeing only single packets at a time that's normal - switches drop MAC addresses after a while and re-learn them. While the MAC is not in the MAC address table the packet is flooded to all ports. That means that Wireshark will also see it. After the flooding of the packet, the MAC is relearned and the flooding stops.

answered 11 Aug '15, 23:33

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Thanks Jasper but the extra captured traffic is not broadcast, i see tcp conversations.

(12 Aug '15, 02:49) Mahmoud Saad
1

yep, I was talking about unicasts. They get flooded by the switch if the MAC address is unknown. You should only see single packets, not full conversations though. If you see full conversations your switch may have fallen back into "flood all" mode, which usually only happens when it is really overloaded.

(12 Aug '15, 04:07) Jasper ♦♦

Thanks Jasper

(12 Aug '15, 08:40) Mahmoud Saad

@Mahmoud Saad,

If an answer has solved your issue, please accept the answer for the benefit of other users by clicking the checkmark icon next to the answer. Please read the FAQ for more information.

(12 Aug '15, 09:42) grahamb ♦