Switch flood
Hello,
I'm trying to flood a Cisco 2950 switch so it falls over to bridge mode.
I'm using Ettercap to flood the switch. I can see all the MAC's in the CAM table have been used up via the show mac-address-table count command (8,000 in total on a 2950)
However when I run Wireshark to start sniffing I cannot see any unicast data between other hosts, I only see multicast frames (i.e. DHCP traffic etc)
Has anyone done this before or have any idea what I'm doing wrong or not doing ?
Thanks
I'm trying to flood a Cisco 2950 switch so it falls over to bridge mode.
I'm using Ettercap to flood the switch. I can see all the MAC's in the CAM table have been used up via the show mac-address-table count command (8,000 in total on a 2950)
However when I run Wireshark to start sniffing I cannot see any unicast data between other hosts, I only see multicast frames (i.e. DHCP traffic etc)
Has anyone done this before or have any idea what I'm doing wrong or not doing ?
Thanks