NIC acting promiscuously -- how to fix?
Rich Wales
richw at richw.org
Tue Jan 25 14:05:46 PST 2005
Doug Hardie wrote:
> To verify what your interface is accepting use: tcpdump -pei rl0
> That will show the packets that it accepts including the ethernet
> headers. Those headers should all have your MAC address in them
> (send or receive).
Very good suggestion. Thanks.
After running the above command for a while, and examining the output,
it turns out that the large amount of traffic on my external net is
mostly ARP "who-has" requests (sent to the broadcast MAC address).
These are, of course, legitimate.
There is also a relatively small number of multicast packets -- most
of which are MDNS (multicast DNS).
So, I was mistaken; my NIC doesn't have a "promiscuity" problem after
all. Sorry for raising a needless alarm.
Rich Wales richw at richw.org http://www.richw.org
More information about the freebsd-stable
mailing list