NLB Heartbeat/Network Traffic

I am receiving a broadcast packets on my network of Ethertype x886f
 sourced from MAC address 02:01:00:00:00:00 and destination is

 I can see this broadcast as "MS NLB heartbeat"
 and on  some I just see them as "Ethernet II"

 Also I have read the link :

 But I am not able to find the source IP Address / machine.

I am at a loss

Who is Participating?
dckiddConnect With a Mentor Author Commented:
Well, I appreciate the one response.  The tool you recommended is very good, but it did not help solve the issue.

In the end I could not find the offending server that was sending out the NLB broadcasts.  I did just configure another box with NLB and the broadcasts went away.  Almost like once the one server got a response back from another heartbeat, it felt better and stopped all its yelling.  Weird.
bbaoConnect With a Mentor IT ConsultantCommented:
try the latest version of MS Network Monitor 3.2 at

NM32 supports the latest parser for analyzing traffic of MS products.

hope it helps,
bbaoIT ConsultantCommented:
NM32 has a built-in parser to recognize NLB heartbeats.

how did you monitor the traffic?

i think you better use a hub to listen the traffic as normally a switch does not forward any non-broadcasting traffic, therefore you won't see peer-to-peer traffic.

hope it helps,
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.