Ethereal-users: [Ethereal-users] MS-based Ethertype Decode

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Scott Fringer <fringsm@xxxxxxxxxxxxxxxxx>
Date: Fri, 01 Feb 2002 12:21:35 -0500
Hello,
  I'm seeing a good deal (from one host) of traffic of Ethertype x886f
sourced from MAC address 02:01:00:00:00:00 destined to the local
broadcast.  The frames are 1510 bytes in size, and repeat at a rate of
roughly two per second.
  Searching http://standards.ieee.org/regauth/ethertype/type-pub.html I
find the Ethertype is registered to Microsoft.  Brief searches of their
site turn up no information on this Ethertype or MAC address.  The user
of the system is not aware of anything 'enabled' on his Win2000 system
that could be generating this traffic.
  Is there a way to assist in developing a dissector for this traffic?
  Anyone here familiar with this traffic pattern?

Thanks,
 Scott
-- 
Scott Fringer                              Shands Healthcare @ U.F.
Network Systems Analyst                        Gainesville, FL