Date: 18-09-05 14:42
I have a small network.The network ip's are from my isp and are public. Concerning confidentiality I will not give real ip numbers. My gateway is 8x.xxx.xxx.254. On running the cmd tcpdump i get the following:
17:06:04.291201 arp who has fe-8x-xxx-xxx-69.myprovider.com tell fe-8x-xxx-xxx-254.myprovider.com
17:06:04.394213 arp who has fe-8x-xxx-xxx-122.myprovider.com tell fe-8x-xxx-xxx-254.myprovider.com
There are more but I will not write them here becouse they are the same, with slittly differences like ip-number and the number afther the time (which I don't know what is his significance).
The ip's that are showed here aren't used and are blocked to transmit information through gateway. Why do they apare in this case, and why don't apare ip's that are in use at that moment? I tried useing some arguments on the command tcpdump but they showed me the same ... more or less (I am talking about the ip's). Sorry if I didn't wrote correctly.