Problems to look out for are arp requests for the lots sequential ip addresses (or just lots of local ips that don’t get replies). I find on my network this is a dead give away for some hosts have viruses which are trying to spread. More clever ones try to randomise the arps a bit but I have scripts to check for say if a host arps for 150 local ip addresses that don’t exist mark them as doing something dodgy.
Also if you interested in arp related things on the network its worth googling “arp poisoning”. Lots of good info.
If you want to go the static arp route be aware Vista does not obey information inputted using the standard arp command (even though it won’t actually complain).
Most arp traffic I see on standard idling windows boxes are generated by samba, UPNP (disable this where you can!), and bonjour, Apple’s equiv to upnp.
-Chris
-----Original
Message-----
Learn to love the arp command’s –s switch and start entering static arp entries. And while you’re at it, use static IP addresses and get rid of those pesky DHCP broadcasts. ;-)
Seriously though, it only looks like a lot. If you were to set up a network monitoring station running something like NTOP, you’d see that as a percentage of total traffic and bandwidth, the ARP broadcasts would not be significant. ARP packets are small and are ignored by every machine unless they’re the machine that needs to respond. Take a look at the requesting stations. On my network the big ARP broadcasters tend to be domain controllers, files and print servers, and routers. I wouldn’t be surprised if that’s what you found. Just about everyone who’s started using a traffic analyzer has been surprised by the number of broadcasts on their networks.
From:
wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Pablo Brozovich
I am looking
at a 200-second trace with 10,511 packets, in this case there are 7,720 ARP
packets (73.45%). Can I take it easy? What can I do to reduce those ARP packets
in the network's traffic? Sent: 22/7/2009 6:22:22 PM To: Community support list for Wireshark Subject: Re: [Wireshark-users] Why are there a lot of ARP traffic inanetwork?
El mejor servicio de email de clase mundial ahora en México. Conóce Mail2World. |
- References:
- Re: [Wireshark-users] Why are there a lot of ARP traffic inanetwork?
- From: John Martin [john.martin@xxxxxxxxx]
- Re: [Wireshark-users] Why are there a lot of ARP traffic inanetwork?
- Prev by Date: [Wireshark-users] Pcap file conversion
- Next by Date: [Wireshark-users] Bug 3547 from 1.2.0 still present in 1.2.1
- Previous by thread: Re: [Wireshark-users] Why are there a lot of ARP traffic inanetwork?
- Next by thread: [Wireshark-users] enterprises.9
- Index(es):