Nelson Law wrote:
> Thanks so much...
>
> All the captures are captured from the switch port which is running EAPS 
> directly and without using any mirroring port.
>   
I'd say "buggy driver - or buggy firmware on the Broadcom NIC".  The 
packets look as if the SNAP header after the LLC header has been trashed 
(overwritten with 00 00 00 aa aa).

You should probably ask Broadcom about that.
_______________________________________________
Wireshark-users mailing list
Wireshark-users@wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-users

Reply via email to