Re: [fw-wiz] Windows dynamic ARP

On Wed, 26 Nov 2008, Darden, Patrick S. wrote:

Some possibilities you might have already thought of for doing this in a
roundabout fashion:

1. If you are using advanced switches, you can implement this on them.
Allow only certain MACs to connect to your network. 2. If your switches

I can MAC-lock switch ports, however what I'm looking for is a host-level
backup to MAC locking the network layer, so that if there's a network
compromise, or a hub is introduced in to the physical topology the game is
not immediately lost.

don't have the ability to do #1, perhaps your switches, core switches,
or core router can filter out ARP requests/replies. 3. You can turn off

ARP won't cross a router- I'm specifically trying to shore up the host OS
so that the host/network seperation still happens, but there's a layer of
protection if the network layer or administrator is compromised.

ARP response in windows (not quite what you wanted, I think)

Hmm, that looks mostly like it's a unicast/multi-and-broadcast switch-
maybe there's someone who's done enough firewall code who can point me to
a good shim location? The built-in firewall seems to be IP layer only.

I'm going to have a good play with /32ing the subnet mask and adding a
routing table entry for each host, but I really think that's going to end
up being sub-optimal- as is adding a null static entry for every IP
address I don't want to communicate with in the subnet (I'm betting the
ARP table is a linear search in most network stacks.)

Paul D. Robertson "My statements in this message are personal opinions
paul@xxxxxxxxxxxx which may have no basis whatsoever in fact."

firewall-wizards mailing list

Relevant Pages

  • Re: Port 21 open on pcs not running ftp?
    ... All of the pcs are on the local network, ... firewalls in place are the windows xp firewall included in sp2. ... that the open port doesn't appear locally. ... Our network switches are Dell powerconnect gigabit switches which ...
  • Re: [fw-wiz] Windows dynamic ARP
    ... The Gratuitous ARP is sent out when the windows machine is first booting up--it is checking to see if it is duplicating anybody's IP address. ... If you are using advanced switches, you can implement this on them. ... Allow only certain MACs to connect to your network. ... protection if the network layer or administrator is compromised. ...
  • Circa 1976, Long Distance Network Mapping Project [telecom]
    ... I had the opportunity to do some university level work in the 1970s related to the cost of operation and ROI feasibility for long-line costs over the old Bell Operated Public Switched Telephone Network. ... calls would default to a route based on what was termed a "homing" priority. ... There were five levels of ranked switches, or a hierarchy of switches based on where calls needed to go. ... For example, under the strict homing hierarchy-topology, a call from Walla Walla, Washington to Moscow, Idaho - a distance of less than 100 miles - would route from Walla Walla, to Yakima, to Seattle, to Sacramento, to Denver, to Salt Lake, to Boise, to Coeur d'Alene and finally to Moscow. ...
  • Re: Single domain two IP subnets
    ... hardware or any of the complexities of "network hardward ... I never criticize anyone's typing as long as the words can ... Cisco ISL VLANS are history. ... Newer Cisco switches don't even support ISL ...
  • Re: FCC now planning "all-IP" phone transition [Telecom]
    ... With VOIP, the customer understands that he/she must provide the power, including battery backup power if desired. ... > copper is capacity. ... to the network also provides operating power. ... > surplus dozens of backbone ESS switches and probably hundreds ...