Solved

How to interpret Wireshark statistics endpoints screen output.

Posted on 2011-09-22
2
1,147 Views
Last Modified: 2012-06-27
If I run the statistics>endpoints on a trace I come up with Ethernet tab (6), IPv4 (19) and TCP (715)

It appears to me to mean that there are 6 mac addresses communicating on the spanned port, and those mac addresses are using 19 ip addresses and those 19 ip addresses are using using 715 ip and port combinations?

Is this correct or do I not understand correctly?
0
Comment
Question by:Dragon0x40
2 Comments
 
LVL 77

Accepted Solution

by:
arnold earned 250 total points
ID: 36586824
It is partially incorrect.

Ethernet deals with MAC addresses seen.
IPv4 Deals with how many distinct IPs are seen (both local and remote, to and from traffic).
TCP deals with breaks down by the distinct on ip/port (i.e. you have 5 unique devices plus broadcast that are accessing 14 other unique IPs which at the time of the snapshot might mean that each of the 5 generated many web requests. While the destination ip/port remains the same, the source of the request changes. Sort by address in the tcp tab, and you will see that your local hosts will have multiple port references.)
0
 
LVL 21

Assisted Solution

by:Rick_O_Shay
Rick_O_Shay earned 250 total points
ID: 36586880
It means that is what has been seen sending packets at the point you are capturing but remember you are going to see IP and port information for such things as broadcasts and multicasts etc. which are all going to be coming from the same switch or router MAC address.

Also every session the device is a part of will be another endpoint with the IP and TCP/UDP info of the remote partner device.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now