Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Re: Solution to ARP spoofing on 3560 and 2960 switches please

Reply
Thread Tools

Re: Solution to ARP spoofing on 3560 and 2960 switches please

 
 
Muffelmampf@googlemail.com
Guest
Posts: n/a
 
      04-20-2008
Hi,

you might try XArp2 to monitor LAN subnets. Have a look at it here:
http://www.chrismc.de/development/xarp/

Regards,
Chris

On Apr 8, 4:54 pm, Sanal Kisi <sanalk...@yahoo.com> wrote:
> Hi,
>
> We have a Cisco6500 as the backbone and a 3560 as router in each of
> the edges (buildings). Connected to 3560's there are 2960's. Each of
> the buildings have their own VLAN/subnets.
>
> Recently we found out that infected PC's in every building are sending
> strange ARP packets and announcing themselves as the gateway of the
> subnet/VLAN. As a result, instead of using the real gateway (the 3560)
> all the other users start communicating with the infected PC thinking
> it is the gateway.
>
> With this strategy, the infected PC serves as the gateway when
> communicting with the normal PC's but also injecting extra
> virus/infections when providing data to them.
>
> I have found that this operation is called Address Resolution Protocol
> (ARP) spoofing, also known as ARP poisoning or ARP Poison Routing
> (APR). (http://en.wikipedia.org/wiki/ARP_spoofing).
>
> As a solution DHCP spoofing (Dynamic ARP Inspection.) is recommended
> (http://en.wikipedia.org/wiki/DHCP_snooping). The only problem here is
> that, 3560's support "Dynamic ARP Inspection" but not the 2960's.
>
> I want to believe and hope that there is a solution available to this
> problem which affects our thousands of users.
>
> Regards.


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Solution to ARP spoofing on 3560 and 2960 switches please News Reader Cisco 0 04-10-2008 06:17 PM
Re: Solution to ARP spoofing on 3560 and 2960 switches please Paul Matthews Cisco 0 04-09-2008 07:46 PM
Re: Solution to ARP spoofing on 3560 and 2960 switches please Trendkill Cisco 7 04-09-2008 03:50 PM
Re: Solution to ARP spoofing on 3560 and 2960 switches please News Reader Cisco 0 04-09-2008 03:15 PM
2960 (layer 2) vs 3560 (layer 3) ...considerations? Ned Cisco 3 09-15-2006 05:55 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57