10:46:37.177662 IP 10.72.135.146.33645 > dns1.*******.domain: 48149+ AAAA?
www.google.it. (31)
10:46:37.178292 IP 10.72.135.146.33646 > dns1.*******.it.domain: 20863+ PTR? x.x.x.87.in-addr.arpa. (44)
10:46:37.209059 IP fw.*******.it > 10.72.135.146: ICMP host dns1.*******.it unreachable, length 36
10:46:37.210368 IP fw.*******.it > 10.72.135.146: ICMP host dns1.*******.it unreachable, length 36
10:46:40.014013 00:00:20:01:05:90 (oui Unknown) > Broadcast, ethertype Unknown (0x81d7), length 84:
0x0000: 4e52 0000 2001 0590 0137 0f7b 6eff 0000 NR.......7.{n...
0x0010: 0000 0000 c000 2100 0e8d 0500 0100 2300 ......!.......#.
0x0020: 00f2 0e00 004c 414e 7461 7374 6963 2d47 .....LANtastic-G
0x0030: 726f 7570 0445 3230 3236 3638 2020 2020 roup.E202668....
0x0040: 2020 2020 0000 ......
10:46:40.103773 IP 10.72.135.140.netbios-ns > 10.72.135.159.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
10:46:40.852599 IP 10.72.135.140.netbios-ns > 10.72.135.159.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
10:46:41.602520 IP 10.72.135.140.netbios-ns > 10.72.135.159.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
10:46:42.177225 arp who-has waterwall tell 10.72.135.146
10:46:42.177309 IP 10.72.135.146.33648 > dns2.*******.it.domain: 48149+ AAAA?
www.google.it. (31)
10:46:42.177319 arp reply waterwall is-at 00:1b:11:6e:90:aa (oui Unknown)
10:46:42.178266 IP 10.72.135.146.33649 > dns2.*******.it.domain: 20863+ PTR? x.x.x.87.in-addr.arpa. (44)
10:46:42.208683 IP dns2.*******.it.domain > 10.72.135.146.33648: 48149 2/1/0 CNAME[|domain]
10:46:42.208878 IP 10.72.135.146.33650 > dns1.*******.it.domain: 18331+ A?
www.google.it. (31)
10:46:42.210654 IP dns2.*******.it.domain > 10.72.135.146.33649: 20863* 1/2/2 (139)
10:46:42.210883 IP 10.72.135.146.33651 > dns1.*******.it.domain: 45085+ PTR? 146.135.72.10.in-addr.arpa. (44)
10:46:42.354813 IP 10.72.135.140.netbios-ns > 10.72.135.159.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST