IDS mailing list archives

filtering ARP and detecting ARP spoofing


From: falcifer <falcifer2001 () yahoo es>
Date: 15 Apr 2003 01:02:24 +0000

Hi
I've 2 questions:

1- Are there any way to filter ARP packets on Linux (I've heard about
arptables but I wasn't able to find how can I use it)

2-In a environmet with a dynamics IPs, how can implement a IDS to detect
arp spoofing? what rules could I implement for it? are any Cisco switch
that implement any of these features?

Thanks at all
-- 
falcifer <falcifer2001 () yahoo es>


------------------------------------------------------------------------------
INTRUSION PREVENTION: READY FOR PRIME TIME?
 
IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - 
including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention. 
 
Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: 
http://www.securityfocus.com/IntruVert-focus-ids



Current thread: