In most cases, clients are talking to servers to support services requested by users. We typically should not see clients communicating directly with other clients on our subnets, unless there is some file sharing or other type of expected activity.

In this video, we will look at how to filter for intra-subnet conversations - clients talking directly to other clients - and examine what normal vs. abnormal traffic looks like. We will see one client performing a TCP port scan and how to filter for open ports.


Author Profile - Chris Greer is a Network Analyst for Packet Pioneer LLC and a Certified Wireshark Network Analyst. Chris regularly assists companies in tracking down the source of network and application performance problems using a variety of protocol analysis and monitoring tools including Wireshark. Chris also delivers training and develops technical content for several analysis vendors.