> I've tested some sniffers with and without WinPCap (W2K SP4), but they 
> all are not capable to capture local traffic (at least on my box).
> Is this normal?  

It does seem to be the case.  

Raw sockets monitors a specific IP address, but presumably the routing 
table bypasses this if the IP address is the same.  WinPcap monitors an 
ethernet adaptor, and local traffic does not go through this.  

Fortunately I have four servers with different OSs for testing on my 
network.  

An unrelated question.  WinPcap shows a vast number of packets being 
broadcast around my network with an ethernet protocol of x88AD, which 
is not in documents I can find, nor does Ethereal describe it.  Not 
quite sure which MAC address is sending them, but some MACs are 
replying.  Has anyone any ideas what this protocol is?  

Angus
-- 
To unsubscribe or change your settings for TWSocket mailing list
please goto http://www.elists.org/mailman/listinfo/twsocket
Visit our website at http://www.overbyte.be

Reply via email to