Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ARP servers
From: Chris Brenton <cbrenton @ sover . net>
Date: Wed, 26 Nov 1997 15:23:55 -0500
To: ed @ alcpress . com
Cc: firewalls @ GreatCircle . COM
References: <199711261521 . 00000025 @ ns . alcpress . com>
Reply-to: cbrenton @ sover . net

Ed Sawicki wrote:

> I notice that some Unix hosts allow for the publishing
> of one or more hosts in their ARP tables using the "pub"
> parameter in a "arp -s" command. This allows the host
> to respond to ARP requests on behalf of other hosts.
>
> 1. Under what conditions is this useful?

This can be very useful if you are running NAT on a firewall. For
example, let's say that the external interface of your firewall is
192.168.1.2. Let's also assume that you have 5 internal SMTP servers.
The "pub" function, along with a static mapping NAT firewall, would
allow you to use IP addresses 192.168.1.3 - 192.168.1.7 for each of the
internal mail hosts. "pub" tells the underlying OS to respond to ARP
requests from other devices on the subnet (like the router sitting
between you and your ISP).


> 2. What are the security implications of this?

Humm. Could cause a denial of service in the wrong hands but no more so
then a machine configured with the wrong IP address.


> 3. Do firewalls deal with this issue at all?


See item #1. :)

Cheers,
Chris

--
**************************************
cbrenton @
 sover .
 net
http://www.amazon.com/exec/obidos/ISBN=0782120822/0740-8883012-887529

"We've heard that a million monkeys at a million keyboards
could produce the Complete Works of Shakespeare; now,
thanks to the Internet, we know this is not true."




References:
Indexed By Date Previous: Re: Network Address Translation Security
From: Jesse Brown <bextreme @ pobox . com>
Next: Re: freeware SSH for WIn95/NT
From: "H. Morrow Long" <morrow . long @ yale . edu>
Indexed By Thread Previous: Re: ARP servers
From: Jason Harper <security @ truedesign . com>
Next: Re: ARP servers
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>

Google
 
Search Internet Search www.greatcircle.com