This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have three machines that are part of the same network - computer A, which is running Wireshark, computer B, and printer C. I have a packet capture log showing computer B's MAC address flooding the network with unicast ARP requests to printer C's MAC address, asking about the owner of printer C's IP address and asking for a response to computer B's IP address. Printer C is disconnected from the network when this happens. How can Wireshark running on computer A be recording this, given that all of the ARP requests are unicast, not broadcast?

asked 06 Mar '17, 20:07

jdm's gravatar image

jdm
6112
accept rate: 0%


ARP request is broadcast, not unicast. This is why it is ARP'ing in the first place...to find the mac address with the destination IP address. Look at the destination mac in the L2 Ethernet header, it will be FF:FF:FF:FF:FF:FF

permanent link

answered 06 Mar '17, 21:08

Rooster_50's gravatar image

Rooster_50
23891218
accept rate: 15%

edited 06 Mar '17, 21:11

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×78
×9

question asked: 06 Mar '17, 20:07

question was seen: 943 times

last updated: 06 Mar '17, 21:11

p​o​w​e​r​e​d by O​S​Q​A