Solved

How to interpret Wireshark statistics endpoints screen output.

Posted on 2011-09-22
2
1,106 Views
Last Modified: 2012-06-27
If I run the statistics>endpoints on a trace I come up with Ethernet tab (6), IPv4 (19) and TCP (715)

It appears to me to mean that there are 6 mac addresses communicating on the spanned port, and those mac addresses are using 19 ip addresses and those 19 ip addresses are using using 715 ip and port combinations?

Is this correct or do I not understand correctly?
0
Comment
Question by:Dragon0x40
2 Comments
 
LVL 76

Accepted Solution

by:
arnold earned 250 total points
ID: 36586824
It is partially incorrect.

Ethernet deals with MAC addresses seen.
IPv4 Deals with how many distinct IPs are seen (both local and remote, to and from traffic).
TCP deals with breaks down by the distinct on ip/port (i.e. you have 5 unique devices plus broadcast that are accessing 14 other unique IPs which at the time of the snapshot might mean that each of the 5 generated many web requests. While the destination ip/port remains the same, the source of the request changes. Sort by address in the tcp tab, and you will see that your local hosts will have multiple port references.)
0
 
LVL 21

Assisted Solution

by:Rick_O_Shay
Rick_O_Shay earned 250 total points
ID: 36586880
It means that is what has been seen sending packets at the point you are capturing but remember you are going to see IP and port information for such things as broadcasts and multicasts etc. which are all going to be coming from the same switch or router MAC address.

Also every session the device is a part of will be another endpoint with the IP and TCP/UDP info of the remote partner device.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now