Home page logo
/

wireshark logo Wireshark mailing list archives

eth.fcs==0x00000000
From: Stuart Kendrick <skendric () fhcrc org>
Date: Sat, 24 Nov 2012 13:27:00 -0800

I'm seeing ARP Requests and Responses with the Ethernet Frame check
sequence set to all zeros .... the expert layer flags these as 'Ethernet
Frame Check Sequence Incorrect'

Tentatively, all the emitters of these ARPs are Windows guests on a
VMWare cluster ...

I captured all ARPs in this particular data center for an hour+ ...
~307,000 ... of which 1100 have an Ethernet FCS of 0x00000000

I've focused on a handful of these ... for one of these VMs (an AD
domain controller), /every single ARP/ which it emits sports an FCS of
0x00000000
For the other handful on which I've filtered, they are mixed:  in some
cases, just a few such ARPs, in other cases mostly but not all.

Anyone recognize this?

--sk

Stuart Kendrick
FHCRC


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]