Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).

ARP spoofing on UBT and PBT

This thread has been viewed 5 times
  • 1.  ARP spoofing on UBT and PBT

    Posted Jul 15, 2024 02:52 AM

    Hello, there is a client that im dealing with is having an issue where they want to implement ARP spoofing on their network.

    They have multiple sites, some sites are using UBT some PBT. 

    When we enable ARP spoofing, Prohibit-ip-spoof-all and enforce dhcp on wired profile mostly Voip and printers just disconnect right away. On UBT site we tried enabling this, only one static ip client disconnected. We did a failover to another cluster member (L2 cluster) clients went to the other member no problem but when we rebooted that member to move clients to the first cluster member most of them couldn't connect to the network. We unchecked prohibit-arp-spoofing - Prohibit-ip-spoof-all - enforce dhcp and they were able to communicate right away.

    How could we prohibit arp spoofing in a network like this? I don't know if we are missing something or our implementation process is wrong.

    Controller  version = 8.10.0.12 (Can't upgrade to 8.12 due to old APs on the site)

    Thank you