Stephane Grobety
Tue Mar 5 14:32:53 GMT 2002

Could be several things:

1/ A web server with more than one IP on it's NIC.
2/ A router simply passing along traffic from another network segment.

SK> While running a sniffer on my network I'm seeing one particular device that is
SK> generating a considerably higher amount of HTTP traffic than any other.

SK> This sniffer shows both the Mac and Ip address, in the case of this particular 
SK> device the mac address always stays the same but the ip address keeps changing 
SK> after about every four packets that it sends. Every other mac address I see 
SK> has a consistent ip associated with it. Is this somebody spoofing ip 
SK> addresses? If so how do I shut them down if I don't know their real ip
SK> address?

SK> Or am I just being a paranoid newbie?

SK> Thanks
SK> Scott

