Endpoints

Devices that communicate over a network are referred to as endpoints. Endpoints in a local area network communicate using a physical address that is MAC address. In a switched environment, communication takes place using physical addresses; switches store MAC address table and work on layer 2 of TCP/IP model.

Let's say, for example, that we are observing the heavy flow of network traffic from certain endpoints, which is kind of unusual based on our playbook data (usual traffic pattern). To identify the exact endpoint from which the superfluous flow of network traffic is generated, the Endpoints dialog comes to the rescue. To access it, click the Endpoints option under the Statistics menu. The Endpoints windows look quite like the ...

Get Wireshark 2 Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.