USG40 log entry: possible ARP spoofing
Hi,
the following entry pops up in the firewall log periodically:
Possible ARP spoofing attack on IP 192.168.1.140. Current hardware address is XXX
where XXX is the correct MAC address for the IP.
The IP used to belong to another device.
Question: how can I get rid of the entry? It is only a minor nuisance, but still...
thank you
the following entry pops up in the firewall log periodically:
Possible ARP spoofing attack on IP 192.168.1.140. Current hardware address is XXX
where XXX is the correct MAC address for the IP.
The IP used to belong to another device.
Question: how can I get rid of the entry? It is only a minor nuisance, but still...
thank you
0
All Replies
-
Hi @copossum,
You need tp enter CLI "no arpseal activate" to turn off it.Router(config)# no arpseal activateRouter(config)# writeDon't miss this great chance to upgrade your Nebula org. for free!
0 -
hi,thank you for your kind answer.what exactly does this command do? I ask because we have entries in the ARP table that we need to be there in order for WoL to work.Also, I tried removing the entry for IP 192.168.1.140 with the commandno arp 192.168.1.140followed by the write command, but that does not change anything, the entry is still there.thank you again
0 -
Hi @copossum,It's mechanism to detect if someone (Man-in-the-middle) is trying to do ARP Spoofing in this network.The attacker uses a spoofing tool, such as Arpspoof or Driftnet, to send out fake ARP packets.We would not suggest to disable it since it would cause network issue when it have ARP Spoofing in this network.
Don't miss this great chance to upgrade your Nebula org. for free!
0 -
hi, thank you,just to be clear: the command "no arpseal activate" is a mechanism to detect if someone is trying to do ARP Spoofing?
and you do not recommend it?
0 -
Hi @copossum,
This is just a CLI to turn off detection. We would suggest to check why your Lan have device doing ARP spoofing. It is abnormal in layer 2 network.Don't miss this great chance to upgrade your Nebula org. for free!
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 131 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 178 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight