The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Detection of ARP spoofing

Prev Next

ARP (Address Resolution Protocol) Spoofing detection is accomplished by mapping a table of IP address to corresponding MAC addresses. The detection of multiple ARP reply packets with a different sender MAC address than its mapped IP results in an alert. Check Attack Log for ARP spoofing-related alerts.

In ARP spoofing, the MAC address of a spoofed ARP packet is the real MAC address of the host attempting the spoofing.

Sometimes misconfiguration (two different machines are using the same IP address) and occasionally system malfunction (host or switch) may result in such ARP spoofing packets.

The following CLI commands are also provided to assist with the ARP Spoofing detection feature:

  • arp delete removes a single MAC/IP address association from the database.

  • arp dump puts the contents of the current MAC/IP address mapping table in the database to the Sensor.dbg file, where it can be used by Technical Support for debugging purposes.

  • arp flush deletes the contents of the MAC/IP addresses mapping table.

  • arp spoof enable enables ARP spoofing detection. (This is akin to enabling it within the Manager interface.)

  • arp spoof disable disables ARP spoofing detection.(This is akin to disabling it within the Manager interface.)

  • show arp spoof status displays whether the ARP spoofing feature is currently enabled or disabled.

Detection of ARP Spoofing results in the triggering of ARP Spoofing alerts. These alerts display in the Attack Log component of Manager. Their names are prefixed with "ARP:" (for example, "ARP: ARP Spoofing with Different MAC Addresses").