IDS mailing list archives

AW: filtering ARP and detecting ARP spoofing


From: "Michael C. Fritz" <micfric () honeynet at>
Date: Thu, 17 Apr 2003 12:04:30 +0200

Hi,
just one more suggestion.
It´s pretty old-school but still effective.
-> use portbased mac-address assignment on your (cisco)switch.
This should be the first step - and then integrate the other mentioned tools
for watching traffic on the wire.

greets mic

------------------------------------------------------------------------------
INTRUSION PREVENTION: READY FOR PRIME TIME?

IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities -
including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention.

Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: 
http://www.securityfocus.com/IntruVert-focus-ids



Current thread: