我使用 Wireshark 捕获了下面的数据包:
...
350 18.942762436 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.210.32.75? Tell 13.210.32.78
351 18.947224197 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.107.32.77? Tell 13.107.32.78
...
368 19.653461468 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.107.32.77? Tell 13.107.32.78
369 19.654293156 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.210.32.75? Tell 13.210.32.78
...
376 20.357944097 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.107.32.77? Tell 13.107.32.78
377 20.459654012 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.210.32.75? Tell 13.210.32.78
...
394 21.272770682 d0:07:ca:0b:63:0c -> Broadcast ARP 60 Who has 13.107.32.77? Tell 13.107.32.78
395 21.273020974 13.107.32.76 -> 171.212.195.23 SSH 198 Encrypted response packet len=132
396 21.273069296 13.107.32.76 -> 171.212.195.23 SSH 198 Encrypted response packet len=132
397 21.273313686 13.107.32.76 -> 171.212.195.23 SSH 1050 Encrypted response packet len=984
398 21.277685816 13.107.32.76 -> 171.212.195.23 SSH 206 Encrypted response packet len=140
399 21.277738698 13.107.32.76 -> 171.212.195.23 SSH 354 Encrypted response packet len=288
400 21.293977041 171.212.195.23 -> 13.107.32.76 SSH 102 Encrypted request packet len=36
401 21.293998326 13.107.32.76 -> 171.212.195.23 TCP 66 ssh > 26048 [ACK] Seq=58305 Ack=73 Win=312 Len=0 TSval=1735797175 TSecr=577413136
你看,有多个 ARP 请求13.210.32.75
和13.107.32.77
,在上面我还找到了 ARP 请求13.210.32.74
和 同一个 VLAN 下的其他 IP。
为什么会出现这种情况?这是正常的吗?还是第 3 层 ARP 表有任何问题?或任何广播风暴?