RE: Anti netcut (was Re: [m0n0wall] m0n0wall 1.3b17)

"Mohammed Ismail" <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
So it is layer 2, then we need layer2 in m0n0wall 
What about broadcasting himself ?
Tells every body that m0n0wall is on MAC IP every 1 sec,
Like spoofing client's arp table each second,, 
How about this? Some how it helps clients to stay connected to m0n0wall
instead of attacker,
And having static ARP table in m0n0wall protect m0n0wall it self.
I put arp.txt contain a list of MAC IP Pairs
And tell m0n0wall to execute 
Arp -f /var/db/cpelements/arp.txt
The problem is we cannot afford switches capable of layer2 filtering,
And there must be other solution, and it could be done with FreeBSD, I just
do not know how exactly, but I guess it will be set of rules
1- static ARP table
2- assign /32 subnetmask for clients 
3- spoof network with m0n0wall real MAC IP pair every x sec
And notice that not only netcut and spoofing there are also worms that arp
poison the network, and such worms uses client IP table so if the client is
isolated in his own subnetmask is not that enough?
,,
Sorry for being annoying but it had been annoying me since a while,
Best Regards.

Mohammed
..


-----Original Message-----
From: Chris Buechler [mailto:[email protected]] 
Sent: Thursday, April 30, 2009 10:37 PM
To: [email protected]
Subject: Re: [m0n0wall] Anti netcut (was Re: [m0n0wall] m0n0wall 1.3b17)

On Thu, Apr 30, 2009 at 5:22 PM, Mohammed Ismail <[email protected]> wrote:
>
> With Special requirements in DHCP server which FreeBSD provides,
> And the secondary IP option, IPfilter.
> if you assigned to a client 10.10.10.30/32 with Default Gateway 1.1.1.1
> and block all traffic to 10.0.0.1 except DHCP and DNS, ICMP 8 and 11 to
have
> Ping and trace route working
> this client will only see and talk with 1.1.1.1 only.
>

No. ARP is layer 2, and unless you segregate the network into multiple
broadcast domains, or implement other controls on your switches,
you're doing nothing to prevent or limit ARP poisoning. It makes no
difference what IP or subnet you're using, if I'm on the same
broadcast domain as you and your switch doesn't prevent it, I can ARP
poison you.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.