On Tue, Dec 4, 2012 at 9:44 AM, Wade Blackwell <[email protected]> wrote: > Thanks Chris, > Rogue DNS entries, emap connections being sent into space. So if the > 0x0000 checksum is normal why is wireshark flagging it as incorrect/corrupt? >
Because it's not correct. But it's normal in many circumstances for BPF listeners to get null checksums on egress traffic (NIC adds the checksum later), which is why they added "maybe checksum offloading?" to that warning in Wireshark, as it confused a ton of people. Happens on every widely-used OS. _______________________________________________ List mailing list [email protected] http://lists.pfsense.org/mailman/listinfo/list
