Firewall Wizards mailing list archives

Re: Windows dynamic ARP


From: robbie.jacka () regions com
Date: Wed, 26 Nov 2008 09:09:05 -0600

I'm pretty sure that what's being sought is a way to prevent Windows from
learning MAC address <-> IP mappings dynamically via ARP. Not sure that
there's a way to do it in Windows; you might be able to block it using the
Windows Firewall, then use the 'arp' command to set your desired ARP
entries persistently.

DHCP won't help. The OP is looking for a method of controlling specifically
what other hosts he's able to speak to, it seems.
--
robbie




                                                                           
             "Dave Love"                                                   
             <dlove@verticalsy                                             
             stemsinc.net>                                              To 
             Sent by:                  "Firewall Wizards Security Mailing  
             firewall-wizards-         List"                               
             bounces@listserv.         <firewall-wizards@listserv.icsalabs 
             icsalabs.com              .com>                               
                                                                        cc 
                                                                           
             11/26/2008 09:05                                      Subject 
             AM                        Re: [fw-wiz] Windows dynamic ARP    
                                                                           
                                                                           
             Please respond to                                             
             Firewall Wizards                                              
             Security Mailing                                              
                   List                                                    
             <firewall-wizards                                             
             @listserv.icsalab                                             
                  s.com>                                                   
                                                                           
                                                                           




What do you mean by dynamic arp entry? ARP maps ips to mac addresses. If
you make a static arp entry aren't you trying to map the ip to the arp
address statically? Why not just use dhcp to do this?

Example:
  > arp -s 157.55.85.212   00-aa-00-62-c6-09  .... Adds a static entry.
  > arp -a                                    .... Displays the arp
table.

-----Original Message-----
From: firewall-wizards-bounces () listserv icsalabs com
[mailto:firewall-wizards-bounces () listserv icsalabs com] On Behalf Of
Paul D. Robertson
Sent: Wednesday, November 26, 2008 8:12 AM
To: firewall-wizards () listserv icsalabs com
Subject: [fw-wiz] Windows dynamic ARP

Does anyone know a way to turn OFF dynamic ARP on Windows?  I'd like to
set up a network where static ARP entries are the only way to
communicate.

Thanks,

Paul
------------------------------------------------------------------------
-----
Paul D. Robertson      "My statements in this message are personal
opinions
paul () compuwar net       which may have no basis whatsoever in fact."
           Art: http://PaulDRobertson.imagekind.com/

_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: