LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-27-2004, 06:51 PM   #1
silvereye
LQ Newbie
 
Registered: Aug 2004
Location: latvia
Posts: 7

Rep: Reputation: 0
Disable dynamic arp


hi

i want to use arp as MAC filtering
i know that on microtic routers this works well and this is the most sipmle and most effective way to filter macs

i have a pretty wide LAN on my neighbourhood and i need MAC filtering to secure my network.

for now i tried
ifconfig eth0 -arp
*eth0 - internal i-face of router
i made a file containig IP's and MAC's of my custumers
arp -f /path/filename adds all this to arp table as static arps
everithing works well for about 10 minutes

after that i cant ping anyone

when i do :
ifconfig eth0 arp
ifconfig eth0 -arp


everything works again - but 10 minutes and network is down

why is this happening ?

what to do?
 
Old 08-27-2004, 10:31 PM   #2
PenguinPwrdBox
Member
 
Registered: Oct 2003
Posts: 568

Rep: Reputation: 31
First, you aren't filtering.

You are specifying in a file, what the Layer 2-Layer 3 mapping is. This simply saves the arp daemon from having to query those machines.
It will still, however, accept new entries.

You need to compile MAC filtering support into your kernel, and do it using iptables.
 
Old 08-28-2004, 04:48 AM   #3
silvereye
LQ Newbie
 
Registered: Aug 2004
Location: latvia
Posts: 7

Original Poster
Rep: Reputation: 0
i know what arp is and i know what it does

and i am sure that it is good way to secure network

you didnt answer my question!!

about iptables - it is nightmare
 
Old 08-28-2004, 09:19 AM   #4
PenguinPwrdBox
Member
 
Registered: Oct 2003
Posts: 568

Rep: Reputation: 31
What you are doing, will not secure a network.
Layer 2 filtering is - you are correct - great security - but not in this method.
You can't control your arp table that finitely, with such little effort......
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange ARP behavior : A linux server responds to all ARP requests Hdvd21 Linux - Networking 4 10-24-2013 05:02 AM
what are the services i can disable, also disable ads, banners in konqueror? greythorne SUSE / openSUSE 3 03-16-2005 08:30 AM
Dynamic name resolution for dynamic IP merlin740 Linux - Software 2 10-04-2004 05:56 PM
Disabling ARP probes after receiving an ARP request AltecLansingMan Linux - Networking 1 03-30-2004 01:25 PM
How to create an proxyarp entry in arp table by using arp command? himalayas Linux - Networking 0 06-04-2003 04:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration