Re: arpwatch

From: John T. Hollyoak (john_at_mail.isc.rit.edu)
Date: 09/11/03

  • Next message: Chris Berry: "Re: Need help from a group of experts. I am not a network expert but I play one on tv."
    Date: Thu, 11 Sep 2003 15:04:35 -0400
    To: security-basics@securityfocus.com
    
    

    Tomas / Zidan,

    I just wanted to respond and add some information and ask a few
    questions....

    a) What switches (that you are aware of) leak? Do you have any other
    information about this? links?
    b) port mirroring or a monitor port, is the way to go. Check out the
    monitor command on the cisco switches, for an example of how to do this.
    Basically maps a range of ports, to a single port, for the purposes of
    monitoring (i've actually used it for an IDS before).
    c) Using a tool within the Dsniff package, called "macof" ... this can be
    accomplished, simply by blasting the CAM table (Content Addressable Memory)
    with alot of addresses. The device will either fail open, or fail closed...
    meaning the basically turn into one big collision domain (hub).

    arpwatch is partially useful, if you have a small network. Anything that
    has a constant amount of ARP requests/replies .... will just create alot of
    junk.

    What are you trying to accomplish by using ARPwatch? Perhaps there is a
    better tool available .....

    John Hollyoak

    ----- Original Message -----
    From: "Tomas Wolf" <tomas@skip.cz>
    To: "zidan" <zidan00@fastmail.fm>
    Cc: <security-basics@securityfocus.com>
    Sent: Thursday, September 11, 2003 7:33 AM
    Subject: Re: arpwatch

    > my 2c --
    > a) some switches horribly leak :-)
    > b) port mirroring would be the best bet (managable switches necessary)
    > c) some under heavy load work like hubs (flood it)
    >
    > good luck - T.
    >
    > zidan wrote:
    >
    > >hello,
    > >
    > >I have recently installed arpwatch on one of our servers. I understood
    > >arpwatch "learns" arp replies, but since arp replies are destined to a
    > >specific MAC and
    > >this is a switched network, how can arpwatch see all arp replies ?
    > >
    > >
    > >-Z
    > >
    > >
    >
    >
    >
    > --------------------------------------------------------------------------
    -
    > Captus Networks
    > Are you prepared for the next Sobig & Blaster?
    > - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
    > - Precisely Define and Implement Network Security
    > - Automatically Control P2P, IM and Spam Traffic
    > FIND OUT NOW - FREE Vulnerability Assessment Toolkit
    > http://www.captusnetworks.com/ads/42.htm
    > --------------------------------------------------------------------------

    --
    >
    ---------------------------------------------------------------------------
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------
    

  • Next message: Chris Berry: "Re: Need help from a group of experts. I am not a network expert but I play one on tv."

    Relevant Pages

    • Re: Port 21 open on pcs not running ftp?
      ... All of the pcs are on the local network, ... firewalls in place are the windows xp firewall included in sp2. ... that the open port doesn't appear locally. ... Our network switches are Dell powerconnect gigabit switches which ...
      (microsoft.public.security)
    • Re: Im stumped by this IT problem
      ... minutes during which users experienced dropped network shares. ... Since then we are experiencing very slow response when opening excel ... if the network switches have a port stats / ...
      (uk.rec.motorcycles)
    • RE: arpwatch
      ... Arpwatch does not require that you use a monitoring port or even that you ... have a managed switch in your network. ... traffic that you will see anywhere on an unmanaged network. ...
      (Security-Basics)
    • Suggestions on getting managed layer 3 switches working
      ... The existing network consisted of a bunch of 10/100 hubs connected together. ... This 7328 has the cable modem connected to port 24 of the switch. ... The last 7328 is not part of the stack and is just hanging off a regular 10/100 port of the 7352. ... After replacing the hubs with the switches, ...
      (comp.dcom.lans.ethernet)
    • Re: Portfast question
      ... network connectivity and downloading A.D. group policies. ... We resolved most of our issues by enabling portfast on the switches ... on a port that a switch is connected to. ...
      (comp.dcom.sys.cisco)