Wireshark-users: [Wireshark-users] IPv6 Multicast Listener Report

From: Wes <wes_r@xxxxxxxxx>
Date: Wed, 17 Sep 2008 12:09:53 -0700 (PDT)
Hi guys,

I noticed a difference between the way Wireshark decodes the attached trace. Note: This is a Docsis trace so you will need to go into Preferences/Protocols/Frames and enable Docsis in case you weren't aware of how to do this.

In Wireshark 0.99.5, these frames show a Ethernet destination of "IPv6-Neighbor-Discovery_XX:XX:XX:XX". With Wireshark 1.0.2, the Ethernet destination shows as "IPv6mcast_XX:XX:XX:XX". Can anyone tell me which one is correct?

Also, my router is dropping the 3rd (I think) frame because the source IP address is not EUI-64 compliant. I see multiple devices using this same fe80::0210:18ff:fe48:1414 source address. Does anyone know if this is normal for this type of packet?

Thanks,

Wes

Attachment: IPv6.pcap
Description: Binary data