On Wed, 2011-05-11 at 07:46 -0600, Dave Taht wrote:
> 
> 
> On Tue, May 10, 2011 at 10:40 PM, Roland Bless <roland.bl...@kit.edu>
> wrote:
>         Hi Dave,
>         
>         On 11.05.2011 05:32, Dave Taht wrote:
>         > 1) in a wireshark analysis, the %interface part is lost
>         
>         
>         But your wireshark is listening on some specific interface,
>         isn't it? 
> 
> No. It is listening on the wildcard interface. Of which there are 8.

Doesn't the pcap header identify the interface in that case?

There is also still the issue (perhaps) of sampled traffic (eg sFlow)
which will have only what was on the wire at the sample point.  Although
presumably there will be some way (not necessarily easy) to work one's
way back through the switch hierarchy to see which host egress port must
have been used since link-local have to be unique with the broadcast
domain and won't traverse a router.

rick jones


_______________________________________________
Bloat mailing list
Bloat@lists.bufferbloat.net
https://lists.bufferbloat.net/listinfo/bloat

Reply via email to