RE: arpwatch

From: Tony Kava (securityfocus_at_pottcounty.com)
Date: 09/11/03

  • Next message: Chris Berry: "Re: Re(2): Possible new virus?"
    To: "'security-basics@securityfocus.com'" <security-basics@securityfocus.com>
    Date: Thu, 11 Sep 2003 14:16:33 -0500
    
    

    Arpwatch does not require that you use a monitoring port or even that you
    have a managed switch in your network. It builds its tables from broadcast
    traffic that you will see anywhere on an unmanaged network. If you network
    uses VLANs this will of course change the situation, but otherwise you can
    run it anywhere even in a switched environment.

    --
    Tony Kava
    Network Administrator
    Pottawattamie County, Iowa
    -----Original Message-----
    From: Zachary Mutrux [mailto:zmutrux@compumentor.org]
    Sent: Thursday, 11 September, 2003 10:59
    To: Security-Basics
    Subject: RE: arpwatch
    I think zidan's question is not "what does arpwatch do?", but "how can I
    intercept arp traffic when my network is switched?" Read more carefully
    before unleashing the rant, J.
    zidan, find the documentation for your switch and see if it has a monitoring
    port that receives all traffic. On better switches you can even define which
    port is the monitoring port.
    Zac
    > -----Original Message-----
    > From: zidan [mailto:zidan00@fastmail.fm]
    > Sent: Wednesday, September 10, 2003 10:33 AM
    > To: security-basics@securityfocus.com
    > Subject: arpwatch
    >
    >
    > hello,
    >
    > I have recently installed arpwatch on one of our servers. I understood
    > arpwatch "learns" arp replies, but since arp replies are destined to a
    > specific MAC and
    > this is a switched network, how can arpwatch see all arp replies ?
    >
    >
    > -Z
    >
    ---------------------------------------------------------------------------
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------
    

  • Next message: Chris Berry: "Re: Re(2): Possible new virus?"

    Relevant Pages

    • Re: Snort/ACID only collecting info for itself, not network
      ... A proper network switch keeps all traffic not destined for you ... > your port. ... Which makes me reiterate an original concern: When I click "portscan ...
      (comp.os.linux.misc)
    • possible arpspoofing
      ... about midnight the network behaves really strange. ... i went there and accessed the switch via ethernet ... the port with the mac-adresse, ... disconnectings, reconnnectings. ...
      (comp.security.misc)
    • Re: One workstation cant access email from ISP - CROSSPOST
      ... Now telnet to Port 110 ... Ethernet adapter Wireless Network Connection: ... Switch is nothing more than a patch panel; ...
      (microsoft.public.exchange.admin)
    • Re: Full Duplex and Hub
      ... but not so much about cards - but network ... and the network being FDX or HDX. ... Since a jam is part of the frame, it's not "filtered by a switch". ... port, ...
      (comp.dcom.lans.ethernet)
    • Connecting Linux Box to company network makes network port shut down
      ... I attach my Suse 8.2 laptop to the company 10/100 Ethernet network ... If I attach the same laptop to another network port on the switch, ...
      (comp.os.linux.networking)