hello. A couple of quick questions based on the convrsation and the snippets of logs shown in the e-mails.
1. Is the MAC address shown in the ARP replies the correct one for the dom0? No reason it should be wrong, but it's worth verifying, just in case there is an unknown host replying on the network. 2. Can you capture the same tcpdumps using the -e flag? The -e flag will print the source and destination MAC addresses, as wel as the source and destination IP addresses or host names, depending on whether you use the -n flag. This might provide additional insight into what's happening on the network. -thanks -Brian