Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2121
  • Last Modified:

NLB Heartbeat/Network Traffic

I am receiving a broadcast packets on my network of Ethertype x886f
 sourced from MAC address 02:01:00:00:00:00 and destination is
 ff:ff:ff:ff:ff:ff

 I can see this broadcast as "MS NLB heartbeat"
 and on  some I just see them as "Ethernet II"

 Also I have read the link :
 http://www.ethereal.com/lists/ethereal-users/200202/msg00013.html

 But I am not able to find the source IP Address / machine.

I am at a loss

Dave
0
dckidd
Asked:
dckidd
  • 2
2 Solutions
 
bbaoIT ConsultantCommented:
try the latest version of MS Network Monitor 3.2 at http://www.microsoft.com/downloads/details.aspx?familyid=f4db40af-1e08-4a21-a26b-ec2f4dc4190d&displaylang=en

NM32 supports the latest parser for analyzing traffic of MS products.

hope it helps,
bbao
0
 
dckiddAuthor Commented:
Well, I appreciate the one response.  The tool you recommended is very good, but it did not help solve the issue.

In the end I could not find the offending server that was sending out the NLB broadcasts.  I did just configure another box with NLB and the broadcasts went away.  Almost like once the one server got a response back from another heartbeat, it felt better and stopped all its yelling.  Weird.
0
 
bbaoIT ConsultantCommented:
NM32 has a built-in parser to recognize NLB heartbeats.

how did you monitor the traffic?

i think you better use a hub to listen the traffic as normally a switch does not forward any non-broadcasting traffic, therefore you won't see peer-to-peer traffic.

hope it helps,
bbao
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now