USG40 log entry: possible ARP spoofing
Hi,
the following entry pops up in the firewall log periodically:
Possible ARP spoofing attack on IP 192.168.1.140. Current hardware address is XXX
where XXX is the correct MAC address for the IP.
The IP used to belong to another device.
Question: how can I get rid of the entry? It is only a minor nuisance, but still...
thank you
the following entry pops up in the firewall log periodically:
Possible ARP spoofing attack on IP 192.168.1.140. Current hardware address is XXX
where XXX is the correct MAC address for the IP.
The IP used to belong to another device.
Question: how can I get rid of the entry? It is only a minor nuisance, but still...
thank you
0
All Replies
-
Hi @copossum,
You need tp enter CLI "no arpseal activate" to turn off it.Router(config)# no arpseal activateRouter(config)# write0 -
hi,thank you for your kind answer.what exactly does this command do? I ask because we have entries in the ARP table that we need to be there in order for WoL to work.Also, I tried removing the entry for IP 192.168.1.140 with the commandno arp 192.168.1.140followed by the write command, but that does not change anything, the entry is still there.thank you again
0 -
Hi @copossum,It's mechanism to detect if someone (Man-in-the-middle) is trying to do ARP Spoofing in this network.The attacker uses a spoofing tool, such as Arpspoof or Driftnet, to send out fake ARP packets.We would not suggest to disable it since it would cause network issue when it have ARP Spoofing in this network.0
-
hi, thank you,just to be clear: the command "no arpseal activate" is a mechanism to detect if someone is trying to do ARP Spoofing?
and you do not recommend it?
0 -
Hi @copossum,
This is just a CLI to turn off detection. We would suggest to check why your Lan have device doing ARP spoofing. It is abnormal in layer 2 network.0
Categories
- All Categories
- 164 Beta Program
- 1.7K Nebula
- 86 Nebula Ideas
- 62 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 50 Switch Ideas
- 907 WirelessLAN
- 27 WLAN Ideas
- 5.3K Consumer Product
- 172 Service & License
- 294 News and Release
- 65 Security Advisories
- 14 Education Center
- 911 FAQ
- 399 Nebula FAQ
- 249 Security FAQ
- 90 Switch FAQ
- 100 WirelessLAN FAQ
- 18 Consumer Product FAQ
- 55 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 68 About Community
- 51 Security Highlight
Freshman Member
Zyxel Employee