Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Stolen Default Gateway IP

Is there any configuration to prevent the potential impact of somebody taking the default gateway IP and configuring it on a device on the same vlan/network. As devices learn of this new default gateway mac there will be traffic that gets black holed.

2 REPLIES
New Member

Re: Stolen Default Gateway IP

not that I know of.

If we're talking a new device, you could use 802.1X or mac-security on the switch port.

As for devices already on the vlan, use an OS that can lock out users from the network settings.

As for the affect, it would be gradual unless a large number of pc's fired up at the same time. PC's already using the current default gateway would keep using it, dependent on usage and arp timeouts of course. Should be enough time to jump on the issue before it gets out of hand.

Bronze

Re: Stolen Default Gateway IP

Dynamic ARP Inspection was introduced recently to help with this problem: http://www.cisco.com/en/US/products/hw/switches/ps4324/products_configuration_guide_chapter09186a00801cddb9.html

I don't know what other platforms support it.

219
Views
0
Helpful
2
Replies