Static ARP

ARP poisoning attacks, such as those described in Chapter 2, are a real threat to all entities in the same broadcast domain including the gateway. By adding static ARP entries on your gateway for sensitive hosts, you reduce the risk posed by an ARP poisoning attack. In particular, static entries should be made for the default gateway, for any access points, and any servers that exist on your wired network. These entries will protect the gateway from participating in an ARP attack against your primary infrastructure. For instructions on creating static ARP entries at boot time, see Section 6.3.3.

Get 802.11 Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.