nanog mailing list archives

Re: 00:aa:bb:01:23:45


From: Tom Hill <tom () ninjabadger net>
Date: Mon, 24 Aug 2020 16:16:03 +0100

On 20/08/2020 09:53, Baldur Norddahl wrote:

By accident I noticed several of my VPLS instances have
00:aa:bb:01:23:45 in the MAC table. We never sent anything just received
a little traffic from that. Obviously not a real MAC address so I tried
to search Google for it. I find several hits with apparently ADSL users
doing pppd (which we do not have).

Anyone have any idea what this could be?

I do not - but I would isolate the port(s) it's coming from, and pick on
your favourite customer out of the bunch & simply ask them what they
have connected. Given that anyone can pick their own MAC addresses/spoof
MAC addresses, the fastest resolution to this mystery will likely be to
just ask.

Let us know what you find out! :)

-- 
Tom


Current thread: