[Bloat] ipv6 fe80:: addresses, vlans and bridges... borked?

Rick Jones rick.jones2 at hp.com
Wed May 11 12:37:07 EDT 2011


On Wed, 2011-05-11 at 07:46 -0600, Dave Taht wrote:
> 
> 
> On Tue, May 10, 2011 at 10:40 PM, Roland Bless <roland.bless at kit.edu>
> wrote:
>         Hi Dave,
>         
>         On 11.05.2011 05:32, Dave Taht wrote:
>         > 1) in a wireshark analysis, the %interface part is lost
>         
>         
>         But your wireshark is listening on some specific interface,
>         isn't it? 
> 
> No. It is listening on the wildcard interface. Of which there are 8.

Doesn't the pcap header identify the interface in that case?

There is also still the issue (perhaps) of sampled traffic (eg sFlow)
which will have only what was on the wire at the sample point.  Although
presumably there will be some way (not necessarily easy) to work one's
way back through the switch hierarchy to see which host egress port must
have been used since link-local have to be unique with the broadcast
domain and won't traverse a router.

rick jones





More information about the Bloat mailing list