[Fwd:] Nvidia NICs with duplicate mac addresses

The Marvel NIC presents the MAC as what we believe to be part of dot1x
negotiation. These were new Dells out of the box, not yet infected.  If we
disable dot1x on the NIC the problem goes away.


Cisco's Recommendation: Replace the NIC

Robert D. Scott wrote:
> Does this MAC present itself all the time, or just during boot?
> Marvel makes a NIC prevalent in some Dell systems, that presents MAC
> 0c00.0000.0000 during its startup process. If you run port security, and
> several people boot their computer within the cam table expiration period,
> port security will disable the port. You can work around it but it is time
> consuming in large networks where port security are enabled.

I know that this doesn't apply here, but a year or so ago I had a client
that had issues with port security continually dropping an end user's
PC. The problem was the MAC address kept changing from Realtek to Cisco.
Sometimes the same NIC would present both MACs at the same time.

It turned out the box was apparently infected with something. Never
could find anything specific (even when booting the Windows box from
Knoppix and scanning for unusual files) except for some large ADS files
that where apparently encrypted. A clean wipe and complete rebuild of
the box fixed the problem.

