I have a PC with 2 NICs in it. One has all of the normal Stuff, the 2nd NIC has nothing checked in its Properties.
2nd NIC is connected to an SG300-52 Switch setup as General Access, untagged VLAN 101. No RMON/Port Mirroring or anything special. Only looking for Broadcast traffic.
Wireshark is setup to only monitor traffic on the 2nd NIC.
Wireshark for the most part is capturing all of the Broadcast Traffic. Though In the WireShark Buffer and Conversation log I can see other Point to point traffic from Machines that are connected to the same switch, though not the Machine I'm on. They only account for a couple % of the Packet count and only maybe 8 of the few thousand conversations logged.
BackupServer<--> Mail Server
BackupServer<--> SQL Server
RandomPC <--> MS Win Update
ands a few others.
When I look at the Packets, they have a like of TCP DUP ACKs, Retransmissions, and several other things. Even though there seem to be issues with the Packets, why is my Monitoring NIC that's only looking at the Broadcast stuff seeing this other traffic?