00:aa:bb:01:23:45

Tom Hill tom at ninjabadger.net
Mon Aug 24 15:16:03 UTC 2020


On 20/08/2020 09:53, Baldur Norddahl wrote:
> 
> By accident I noticed several of my VPLS instances have
> 00:aa:bb:01:23:45 in the MAC table. We never sent anything just received
> a little traffic from that. Obviously not a real MAC address so I tried
> to search Google for it. I find several hits with apparently ADSL users
> doing pppd (which we do not have).
> 
> Anyone have any idea what this could be?

I do not - but I would isolate the port(s) it's coming from, and pick on
your favourite customer out of the bunch & simply ask them what they
have connected. Given that anyone can pick their own MAC addresses/spoof
MAC addresses, the fastest resolution to this mystery will likely be to
just ask.

Let us know what you find out! :)

-- 
Tom



More information about the NANOG mailing list