NIC addresses and tcpdump?

From: Judith Reed <jreed_at_wukon.appliedtheory.com>
Date: Thu, 21 Jan 1999 14:37:37 -0500

When using tcpdump, I see a lot of traffic on the wire, with specific
MAC addresses. As an example:

14:30:47.325769 0:a0:24:d3:94:db ff:ff:ff:ff:ff:ff 8137 74:

I'm trying to reconcile these MAC address with the output of "arp -a",
but they don't coincide. I have some foggy recollection of the MAC addresses
going thru some translation algorithm when you see them sometimes - can anyone
enlighten me on what I'm seeing?

Also, what is with the ff:ff:ff:ff:ff:ff ? Is that a multicast?

Forgive me if these are obvious, I seldom look at this kind of thing.

Host I'm looking from is running DU 4.0d, and tcpdump is one that came
with the OS.

TIA!!

-- 
Judith Reed
jreed_at_appliedtheory.com
(315) 453-2912 x335
Received on Thu Jan 21 1999 - 19:39:00 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:38 NZDT