cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
488
Views
0
Helpful
1
Replies

Wireshark Analysis

QUARK TARO
Level 1
Level 1

I am capturing the traffic for a particular system using span port. My wire shark analysis shows a flood of communication with source and destination IP listed but these two IP's (source or destination) does not belong to the system I monitor. The coloring of the traffic is RED meaning TCP RST.

Any guess why point to point communication is reaching this particular system where as source and destination IP does not belong to the system?

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

It could be any number of things.

Can you share the span setup and some details about the connected hosts' addresses vs. what you are seeing?

Review Cisco Networking for a $25 gift card