Re: MAC Bindings

From: Seth Arnold (sarnold@wirex.com)
Date: 08/23/01


Date: Thu, 23 Aug 2001 09:33:01 -0700
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com
Subject: Re: MAC Bindings
Message-ID: <20010823093301.R11991@wirex.com>

On Wed, Aug 22, 2001 at 10:56:17AM -0500, m.s. wrote:
> I'm faced with the problem of configuring a Linux router to prevent hosts
> on the network from spoofing ARP requests to prevent ARP-based MiM
> attacks on the network. I haven't been able to find any documentations on
> this matter, and thought asking here would be appropriate. The machine is
> running Linux 2.2.19.

If I am not mistaken, this is pretty much the attack scenario for IPSec:
the hosts are trusted enough to use, the network is untrusted but
available. IPSec, with manually configured host keys, ought to be able
to defend against this attack scenario ably.



Relevant Pages

  • Re: MAC Bindings
    ... > I'm faced with the problem of configuring a Linux router to prevent hosts ... > on the network from spoofing ARP requests to prevent ARP-based MiM ... You can disable arp on youre NIC with ifconfig. ...
    (Focus-Linux)
  • Re: MAC Bindings
    ... > I'm faced with the problem of configuring a Linux router to prevent hosts ... > on the network from spoofing ARP requests to prevent ARP-based MiM ...
    (Focus-Linux)
  • Re: Heavyweight Network Mapping Tools
    ... multiple threads so as not to adversely effect any individual sub network ... The goals for the OPTE project are slightly ... >> Hosts alive through ICMP ... I was loooking more for the vulnerability scanning approach without ...
    (Pen-Test)
  • Re: Scanning Class A network
    ... > within the network to identify hosts and ports exposed to the ... ICMP was not allowed in the network ... ports for all IPs. ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • Very slow SMB performance on one interface of a multi-homed server
    ... one interface and a private gigabit network on the other. ... Of the seven hosts, four are Windows 2000 server and three are XP. ... Connections using the office LAN and, ...
    (microsoft.public.windows.server.networking)