This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,

I am seeing on my network a flood of LLC packets all seeming to come from the same MAC address (which is a mitel phone about 4 switches away from the capturing PC).

Even stranger it is now unpluged and I am still seeing the traffic!!

So I need some help in picking apart the wireshark log and tracking down where this data is coming from.

23535   58.942635000    172.16.225.136  CDP/VTP/DTP/PAgP/UDLD   CDP 121 Device ID: SEP08000F4D55BB  Port ID: Port 1

asked 14 Aug '12, 04:23

DevilWAH's gravatar image

DevilWAH
11334
accept rate: 0%


CDP is a Cisco proprietary protocol. They use it to learn about other switches in the network.

http://de.wikipedia.org/wiki/Cisco_Discovery_Protocol

So, these packets are from one of your switches, that has CDP enabled. It's nothing to worry about, as long as it is not really flooding the network with these packets.

You can disable CDP with this command:

no cdp enable

For further information, please check the Cisco site:

http://www.cisco.com/en/US/tech/tk962/technologies_tech_note09186a00801aa000.shtml

BTW:

I am seeing on my network a flood of LLC packets

What is a flood in that case? How many packtes per second/minute do you see?

Regards
Kurt

permanent link

answered 14 Aug '12, 07:09

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 14 Aug '12, 07:09

As CDP packets are multicast packets, they can be forwarded by switches if they do not absorb them. Cisco switches will receive the CDP packets and not forward them. Maybe your L2 network has a loop that is not blocked anywhere with spanning-tree, maybe only for a specific vlan?

The fact that you have a storm of these messages even after you disconnect the source does suggest a loop too.

What kind of switches are you using and what does the topology look like?

permanent link

answered 14 Aug '12, 10:02

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×16
×9
×5

question asked: 14 Aug '12, 04:23

question was seen: 4,263 times

last updated: 14 Aug '12, 10:02

p​o​w​e​r​e​d by O​S​Q​A