Static ARP table in Linux
From: Gil Disatnik (gil_at_disatnik.com)
Date: 12/11/03
- Previous message: John Davis: "Re: Firewall Inquiry"
- Next in thread: Bill Nash: "Re: Static ARP table in Linux"
- Reply: Bill Nash: "Re: Static ARP table in Linux"
- Reply: Chuck Wolber: "Re: Static ARP table in Linux"
- Reply: Andrei Boros: "Re: Static ARP table in Linux"
- Reply: Felipe Franciosi: "Re: Static ARP table in Linux"
- Reply: Jacek Masiulaniec: "Re: Static ARP table in Linux"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 11 Dec 2003 10:25:20 +0200 To: focus-linux@securityfocus.com
Hello,
I am trying to have a firewall running with a static arp table for it's
local network (I know I know... MAC can easily be changed. The users behind
this firewall are not that advanced, all I want is that people will not be
able to simply plug in a machine and get net access from it...)
Back to business - when bringing up an interface with -arp, it's not only
preventing the machine from adding new MAC entries to it's arp cache, but
it's also stopping it from advertising it's very own MAC address.
Is there a way to prevent the arp cache from being filled yet to still be
able to advertise my own MAC?
I thought about simply forcing the MAC addresses I know into the cache
(perm) and to also add those I don't know with a bogus MAC, that's a really
ugly workaround though.
Any suggestions?
Thanks.
Regards
Gil Disatnik
UNIX system administrator.
GibsonLP@EFnet
http://gil.disatnik.com
_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
apt-get install slackware
--------------------------------------------------------------------
"Windows NT has detected mouse movement, you MUST restart
your computer before the new settings will take effect, [ OK ]"
--------------------------------------------------------------------
Windows is a 32 bit patch to a 16 bit GUI based on a 8 bit operating
system, written for a 4 bit processor by a 2 bit company which can
not stand 1 bit of competition.
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-
- Previous message: John Davis: "Re: Firewall Inquiry"
- Next in thread: Bill Nash: "Re: Static ARP table in Linux"
- Reply: Bill Nash: "Re: Static ARP table in Linux"
- Reply: Chuck Wolber: "Re: Static ARP table in Linux"
- Reply: Andrei Boros: "Re: Static ARP table in Linux"
- Reply: Felipe Franciosi: "Re: Static ARP table in Linux"
- Reply: Jacek Masiulaniec: "Re: Static ARP table in Linux"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|