Décortiquer une requête ARP avec WireShark

Capture d'écran

Voici le texte brut, exporté de la trame (ce que vous voyez dans la capture d'écran ci-dessus) :

No. Time Source Destination Protocol Length Info
51 8.528343 TPLink_d7:9f:85 Broadcast ARP 60 Who has 192.168.10.250? Tell 192.168.10.10

Frame 51: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface \Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB}, id 0
Section number: 1
Interface id: 0 (\Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB})
Interface name: \Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB}
Interface description: vEthernet (COM_EXT)
Encapsulation type: Ethernet (1)
Arrival Time: Feb 7, 2025 12:02:43.548506000 Paris, Madrid
UTC Arrival Time: Feb 7, 2025 11:02:43.548506000 UTC
Epoch Arrival Time: 1738926163.548506000
[Time shift for this packet: 0.000000000 seconds]
[Time delta from previous captured frame: 0.389684000 seconds]
[Time delta from previous displayed frame: 0.389684000 seconds]
[Time since reference or first frame: 8.528343000 seconds]
Frame Number: 51
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:arp]
[Coloring Rule Name: ARP]
[Coloring Rule String: arp]

Ethernet II, Src: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
Destination: Broadcast (ff:ff:ff:ff:ff:ff)
.... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
.... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
Source: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: ARP (0x0806)
[Stream index: 1]
Padding: 0000000000000000000000000000
Trailer: 20202020

Address Resolution Protocol (request)
Hardware type: Ethernet (1)
Protocol type: IPv4 (0x0800)
Hardware size: 6
Protocol size: 4
Opcode: request (1)
Sender MAC address: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85)
Sender IP address: 192.168.10.10
Target MAC address: 00:00:00_00:00:00 (00:00:00:00:00:00)
Target IP address: 192.168.10.250

Nous allons décortiquer ce paquet capturé par Wireshark afin de comprendre chacune de ses parties.
Ce paquet est une requête ARP (« Address Resolution Protocol ») qui sert à découvrir l'adresse MAC associée à une adresse IP donnée sur un réseau local. Dans cet exemple, l'appareil à l'adresse IP 192.168.10.10 cherche à savoir « qui possède » l'IP 192.168.10.250.

Voici l'explication détaillée :


1. La ligne de résumé

No. Time Source Destination Protocol Length Info
51 8.528343 TPLink_d7:9f:85 Broadcast ARP 60 Who has 192.168.10.250? Tell 192.168.10.10

2. Détails de la trame (Frame 51)

Frame 51: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface \Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB}, id 0
Section number: 1
Interface id: 0 (\Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB})
Interface name: \Device\NPF_{27BB5FB2-E90C-46B8-858A-9AE0317E9CAB}
Interface description: vEthernet (COM_EXT)
Encapsulation type: Ethernet (1)
Arrival Time: Feb 7, 2025 12:02:43.548506000 Paris, Madrid
UTC Arrival Time: Feb 7, 2025 11:02:43.548506000 UTC
Epoch Arrival Time: 1738926163.548506000
[Time shift for this packet: 0.000000000 seconds]
[Time delta from previous captured frame: 0.389684000 seconds]
[Time delta from previous displayed frame: 0.389684000 seconds]
[Time since reference or first frame: 8.528343000 seconds]
Frame Number: 51
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:arp]
[Coloring Rule Name: ARP]
[Coloring Rule String: arp]

3. En-tête Ethernet

Ethernet II, Src: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
Destination: Broadcast (ff:ff:ff:ff:ff:ff)
.... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
.... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
Source: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: ARP (0x0806)
[Stream index: 1]
Padding: 0000000000000000000000000000
Trailer: 20202020

4. Protocole ARP (Address Resolution Protocol)

Address Resolution Protocol (request)
Hardware type: Ethernet (1)
Protocol type: IPv4 (0x0800)
Hardware size: 6
Protocol size: 4
Opcode: request (1)
Sender MAC address: TPLink_d7:9f:85 (a8:42:a1:d7:9f:85)
Sender IP address: 192.168.10.10
Target MAC address: 00:00:00_00:00:00 (00:00:00:00:00:00)
Target IP address: 192.168.10.250

En résumé


⬆️ Retour en haut de la page