ARP (Address Resolution Protocol) Spoofing detection is accomplished by mapping a table of IP address to corresponding MAC addresses. The detection of multiple ARP reply packets with a different sender MAC address than its mapped IP results in an alert. Check Attack Log for ARP spoofing-related alerts.
In ARP spoofing, the MAC address of a spoofed ARP packet is the real MAC address of the host attempting the spoofing.
Sometimes misconfiguration (two different machines are using the same IP address) and occasionally system malfunction (host or switch) may result in such ARP spoofing packets.
The following CLI commands are also provided to assist with the ARP Spoofing detection feature:
arp deleteremoves a single MAC/IP address association from the database.arp dumpputs the contents of the current MAC/IP address mapping table in the database to the Sensor.dbg file, where it can be used by Technical Support for debugging purposes.arp flushdeletes the contents of the MAC/IP addresses mapping table.arp spoof enableenables ARP spoofing detection. (This is akin to enabling it within the Manager interface.)arp spoof disabledisables ARP spoofing detection.(This is akin to disabling it within the Manager interface.)show arp spoof statusdisplays whether the ARP spoofing feature is currently enabled or disabled.
Detection of ARP Spoofing results in the triggering of ARP Spoofing alerts. These alerts display in the Attack Log component of Manager. Their names are prefixed with "ARP:" (for example, "ARP: ARP Spoofing with Different MAC Addresses").