Some IDS do watch for this via "arp flip-flop". In otherwords, a MAC
was associated with one IP, then suddenly another IP. DHCP in a Win2k
environment is basically "static" as long as you have enough Ips. A
workstation will always pull the same IP address from DHCP based on MAC
unless it ran out of Ips and handed out to a new client who didn't
already have an IP previously.

How can i detect an arp-spoofing in a environmet with a dynamic IP? Does
cablemodem operators usually install IDS? where?

