Solved

NLB Heartbeat/Network Traffic

Posted on 2009-04-13
3
2,101 Views
Last Modified: 2013-12-19
I am receiving a broadcast packets on my network of Ethertype x886f
 sourced from MAC address 02:01:00:00:00:00 and destination is
 ff:ff:ff:ff:ff:ff

 I can see this broadcast as "MS NLB heartbeat"
 and on  some I just see them as "Ethernet II"

 Also I have read the link :
 http://www.ethereal.com/lists/ethereal-users/200202/msg00013.html

 But I am not able to find the source IP Address / machine.

I am at a loss

Dave
0
Comment
Question by:dckidd
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 37

Assisted Solution

by:bbao
bbao earned 100 total points
ID: 24190573
try the latest version of MS Network Monitor 3.2 at http://www.microsoft.com/downloads/details.aspx?familyid=f4db40af-1e08-4a21-a26b-ec2f4dc4190d&displaylang=en

NM32 supports the latest parser for analyzing traffic of MS products.

hope it helps,
bbao
0
 

Accepted Solution

by:
dckidd earned 0 total points
ID: 24228034
Well, I appreciate the one response.  The tool you recommended is very good, but it did not help solve the issue.

In the end I could not find the offending server that was sending out the NLB broadcasts.  I did just configure another box with NLB and the broadcasts went away.  Almost like once the one server got a response back from another heartbeat, it felt better and stopped all its yelling.  Weird.
0
 
LVL 37

Expert Comment

by:bbao
ID: 24230790
NM32 has a built-in parser to recognize NLB heartbeats.

how did you monitor the traffic?

i think you better use a hub to listen the traffic as normally a switch does not forward any non-broadcasting traffic, therefore you won't see peer-to-peer traffic.

hope it helps,
bbao
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
An article on effective troubleshooting
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question