Firewall Wizards mailing list archives

Re: Windows dynamic ARP


From: James <jimbob.coffey () gmail com>
Date: Thu, 4 Dec 2008 12:30:13 +1100

On Thu, Dec 4, 2008 at 12:08 PM, James <jimbob.coffey () gmail com> wrote:
On Thu, Nov 27, 2008 at 3:51 AM, Mike O'Connor <mjo () dojo mi org> wrote:
:Does anyone know a way to turn OFF dynamic ARP on Windows?  I'd like to
:set up a network where static ARP entries are the only way to
:communicate.

More IDS than IPS but Xarp will at least report any changes.
If you control the environment you could static map any unused ip
space on each host and then use the Xarp Static preserve filter but a
pretty horrible cludge when al you want is a layer 2 packet filter to
prevent an arp request or reply leaving your hosts.

Actually an easier way would be to use the requestedresponse filter in
Xarp.  This only allows a response if your host generated a request.
If you are static mapping ip to mac you should never generate a
request.



--
jac




-- 
jac
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: