Realize ARP ultimate defence with Look ' n ' Stop fire wall
ARP has attack the question and already been discussed for a lot times, a lot of friends have proposed a lot of solutions too, not wordy here. But my individual proposes, the stronger network engineer to manipulative ability, preferably defending the method that ARP attacks, through setting up the fire wall, make this machine only respond to MAC that the gateway came, this's a basic method solved
Seldom there is this function at present in the domestic fire wall, it is Look ' n ' Stop to be for my personal use, cooperate with the use of patch, very safe carefree
" Look ' n ' Stop fire wall " Powerful, set up and complicated, if the installation of person not familiar with Look ' n ' Stop fire wall has produced various network problems after finishing, had better surf the Net, consult materials, oneself solve some problem, problem solving learn till knowledge also not merely so. Can not really manage to have the forum and ask.
Give to I one-off Look ' n ' Stop as an addition and take precautions against arp gains:
Prevent the network sheriff from waiting for arp to control
Network sheriff whether whom ARp that utilize cheat come, achieve the goal of controlling. ARP agreement is used for analyzing the corresponding relation of IP and MAC, so can realize that the control of the network sheriff is resisted by following methods.
If machine of you does not plan machine communication in the LANs, can then use the following methods:
A.In " Internet filters " There is a " ARP inside: Authorize all ARP packets" The rule, forbid the sign on making in front of this rule;
B.But these regular acquiescence can forbid the information of the gateway, the method dealt with is MAC address (usually the gateway is stationary) of a gateway The ones that place on this rule " The goal " The district, in " Ethernet: The address " Li are chosen " Not equal to " ,And MAC address of a gateway was filled in at that time; Place one's own MAC address on " The source " The district, in " Ethernet: The address " Li are chosen " Not equal to " .
C.In the last " All other packet " In, revise " goal " of this rule The district, in " Ethernet: The address " Li are chosen " Not equal to " ,Fill out FF in MAC address: FF: FF: FF: FF: FF; Place one's own MAC address on " The source " The district, in " Ethernet: The address " Li are chosen " Not equal to " . The others are not changed.
In this way the network sheriff is powerless. This method is not suitable for with other machine communication in the LAN, and the gateway address is under the stationary situation.
If your machine needs only needs to get rid of the control of the network sheriff with the machine communication in the LAN, the following methods are simpler and practicaller (this method has nothing to do with the fire wall) : Enter the order line state, operate " ARP - s gateway IP gateway MAC " Getting all right, want, get MAC of gateway, only Ping gateway, then look over with Arp - a command, the ones that can get IP and MAC of the gateway are corresponding. This method should have commonability even more, and as the net closes the address but well operated when being variable, repeat " ARP - s gateway IP gateway MAC " once Come on. The function of the this command sets up static ARP and analyzes tables.













