< Home

Defense Against ARP Spoofing Attacks

As shown in Figure 1, UserA, UserB, and UserC use Switch to connect to the gateway to access the Internet.

Generally, when UserA, UserB, and UserC go online and exchange ARP packets, ARP entries are created on UserA, UserB, UserC, and the gateway. At the same time, an attacker can send bogus ARP packets to UserA, UserB, UserC, or the gateway in the broadcast domain to modify ARP entries, intercept information, and interrupt communication.

Figure 1 Defending against ARP spoofing attacks

To avoid the preceding problems, deploy ARP spoofing defense functions on the gateway, including ARP entry fixing, strict ARP learning, and gratuitous ARP packet sending. You can deploy DAI on the access device for DHCP users.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic