Hi everyone,

I was wondering if anyone else has seen Win98SE machines
doing arp queries like these:

  Times Source MAC     Source IP         Destination MAC
  ----- -------------- ----------------- -----------------------
   1071 0008:c763:223c srcip=50.46.234.0 destenet=0100:0000:0000
    181 0008:c763:223c srcip=50.46.234.0 destenet=0100:044a:0bbf
    377 0010:a701:8a7b srcip=50.46.234.0 destenet=0100:0000:0000
     30 0010:a701:8a7b srcip=50.46.234.0 destenet=0100:044a:0bbf
    147 0020:18a0:395d srcip=50.46.234.0 destenet=0100:0000:0000
    754 0060:5209:acfd srcip=50.46.234.0 destenet=0100:0000:0000
      7 0060:5209:acfd srcip=50.46.234.0 destenet=0100:0000:0000
    120 0060:5209:acfd srcip=50.46.234.0 destenet=0100:044a:0bbf
    220 0080:ad97:9088 srcip=50.46.234.0 destenet=0100:0000:0000
     20 0080:ad97:9088 srcip=50.46.234.0 destenet=0100:044a:0bbf

These are five unique machines that are having problems doing
ARP queries to our gateways, for obvious reasons.

We just enabled source address filtering in ARP requests, and
started getting drops galore.

The funny thing is that noone here has the source ip "50.46.234.0"
(I've verified their setup) and another funny thing is that half 
of these are requests, so the destination address 
should be 0000:0000:0000 (i.e. "not set")

?

/Mike

-- 
Mikael Olsson, EnterNet Sweden AB, Box 393, S-891 28 �RNSK�LDSVIK
Phone: +46 (0)660 105 50           Fax: +46 (0)660 122 50
Mobile: +46 (0)70 66 77 636
WWW: http://www.enternet.se        E-mail: [EMAIL PROTECTED]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to