L2 security – Address Resolution Protocol (ARP).
I would like to look closer on the ARP protocol, how it works and what kind of security method we can use to control ARP packets.
/----\ /----\
| R1 |----------------| R2 |
\----/\ /\----/
Gig0/0 Gig0/0
10.0.0.1 10.0.0.2
Let’s check what we see in the ARP table:
R1sh arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.0.0.1 - ca02.0eb8.0008 ARPA GigabitEthernet0/0
R1sh arp detail
ARP entry for 10.0.0.1, link type IP.
Interface, via GigabitEthernet0/0, last updated 69 minutes ago.
Encap type is ARPA, hardware address is ca02.0eb8.0008, 6 bytes long.
ARP subblocks:
* Interface ARP Subblock
R1
R2sh arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.0.0.2 - ca03.0eb8.0008
...