I am fairly new at this so any extra information that may help me learn is appreciated. My laptop (which Wireshark is running on) seems to be sending a lot of ARP requests. It seems to be starting at 10.0.0.1 and runs all the way through to 10.0.0.255, asking about each ip multiple times. After it finishes it will stop for something like 15 seconds before starting over again. Statistics from the sample captured show 88 ARP packets in ten seconds. I was also curious about the SNMP requests. Principally I can't think of anything that would be using that destination address, and I never see any response traffic. \ Again, any information at all would be helpful. Thank you much. asked 20 Nov '12, 16:13 kineteks |
One Answer:
This OID tells me you've got a crappy printer manager running, causing all this traffic. answered 20 Nov '12, 23:26 Jaap ♦ |
Thank you! Ended up removing all printers from Printers and Devices. No more SNMP traffic, and I learned a bit about OID's. Now if even has any ideas about the ARP traffic...
Printer usually come with a CD with crappy printer manager software. If you installed it, it may still be scanning your network to find printers.