Re: arpwatch

From: Gunter Luyten (Gunter.Luyten_at_student.kuleuven.ac.be)
Date: 09/11/03

  • Next message: David Lubowa: "Re: HSRP with load balancing on a Cisco IOS based firewall"
    Date: Thu, 11 Sep 2003 11:26:05 +0200
    To: security-basics@securityfocus.com
    
    

    zidan wrote:
    > hello,
    >
    > I have recently installed arpwatch on one of our servers. I understood
    > arpwatch "learns" arp replies, but since arp replies are destined to a
    > specific MAC and
    > this is a switched network, how can arpwatch see all arp replies ?
    >
    >
    > -Z

    Hi,

    ARP uses broadcast packets to discover which MAC address belongs to a
    given IP address. Therefore the requests and also the replies are
    received by every host on the network segment. Your network may be
    switched, but broadcasts are still sent to every connected host.

    Best regards,

    Gunter

    ---------------------------------------------------------------------------
    Captus Networks
    Are you prepared for the next Sobig & Blaster?
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Precisely Define and Implement Network Security
     - Automatically Control P2P, IM and Spam Traffic
    FIND OUT NOW - FREE Vulnerability Assessment Toolkit
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------


  • Next message: David Lubowa: "Re: HSRP with load balancing on a Cisco IOS based firewall"

    Relevant Pages

    • TidBITS#794/29-Aug-05
      ... This week's issue brings a potpourri of Mac news, ... Mark Anbinder looks briefly at Google Talk, ... Adding Tiger's AirPort Preferred Network List ...
      (comp.sys.mac.digest)
    • Apples new software may steal the show
      ... Steve Jobs, Apple Computer's co-founder and performer in chief, rarely shows any reluctance to sell -- or even over-sell -- his company's accomplishments. ... Jobs spent only about five minutes talking about what I see as the big news of the day: Apple's first software for using a home network through a television screen rather than a computer monitor. ... Apple's Mac OS X, the software running all its Macintosh computers, also has built-in features for easily connecting Macs in a network. ...
      (comp.sys.mac.advocacy)
    • Re: OK first real Mac Complaint - Network Trouble
      ... changing the channel on my router has cleared up wireless issues on my ... have to reset it when the connection dies. ... to suck up a large amount of network bandwidth to do unnecessary screen ... It should at least help to identify what the Mac ...
      (comp.sys.mac.misc)
    • Re: About War Driving ..
      ... However, MAC filtering does not qualify as defense in depth, ... because the attacker can spoof a valid IP address. ... broadcasting the SSID doesn't hide a network, but just makes it show up ... machines in your building that you can control and check the MAC ...
      (Security-Basics)
    • Re: Wired security improvements
      ... I have a lot of experience with 802.1x in a wireless environment and it ... option than MAC Authentication via RADIUS as far as security is concerned, ... it can only provide a weak form of network authentication. ...
      (Security-Basics)