This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

A few Questions

0

Configuration information.

Server: X86 Cisco UCS

OS: Windows 2012 R2 Std

Use NMS solution of Watch Tech

WireShark program is installed but occasionally uses.

In the same network where the server is installed, the IPSCAN security equipment.

IPSCAN Role: Probe MAC false advertising and unauthorized devices intended for continuous as the GW MAC (Unicast).

Issue detais IPSCAN security equipment should be updated to Probe MAC (false) for false advertising off target device to capture the ARP MAC (GW direction) of the server to the Windows OS.

ARP Reply is sent to the device as Unicast, it was the situation should not change the ARP cache communication occurs with the destination address and see at any other appropriate server.

Questions

Capture the ARP Reply Packet going to different way, by the NPF Driver is installed WireShark WinPcap Library or the case or to update the ARP inquiry if possible.

Symptoms that occur in state WireShark is not working

Fragmented tests, symptoms that disappear after the deletion is confirmed that WireShark. (When deleting options: Delete, including WinPcap).

if you have solution, we need that.

thanks you

asked 05 Sep '16, 05:41

minwoo%20lee's gravatar image

minwoo lee
6112
accept rate: 0%