Why does no router support ARP Spoofing Defense in Controller mode?

Why does no router support ARP Spoofing Defense in Controller mode?

Why does no router support ARP Spoofing Defense in Controller mode?
Why does no router support ARP Spoofing Defense in Controller mode?
2024-10-19 22:38:50 - last edited 2024-10-30 12:07:26
Tags: #ARP
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.6 Build 20240718 Rel.82712

Hi!

 

Recently, I started delving into ARP Spoofing and ARP Poisoning attacks. Then, I looked into how I could (better) protect my Omada network against this. I saw an option for "ARP Spoofing Defense" in my Omada controller.

 

I enabled it, did an ARP Spoof, but the router didn't do anything.

 

Now I see in the specifications of my ER605 that ARP protection only works in Standalone Mode. That makes some sense since it's a budget device. But even the ER7206 (€142), ER707-M2 (€160), and the brand new ER7412-M2 (€200) from August 2024 (!) can only do this in Standalone mode.

 

For the ER704W-4G (€309) and ER706W (€132) variants, I don’t see an icon for "Sending GARP Packets" and "IP-MAC Binding." Only ARP Scanning has an icon, which means it is only available in Standalone mode.

 

 

Is it true that ARP Spoofing Defense works fully in Controller mode for the ER704W-4G and ER706W variants? Is ARP Scanning necessary for this functionality? Why was this choice made? It seems completely illogical to me based on hardware specifications and price.

 

 

In addition, I noticed that the specifications of the ER8411 have a *5 next to ARP Inspection, but at the bottom, it doesn't say what *5 means. Did you forget to add that, or does the ER8411 actually support ARP Inspection in Controller mode?

 

 

  0      
  0      
#1
Options
10 Reply
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2024-10-20 11:16:13 - last edited 2024-10-30 12:07:26

  @ikheetjeff 

 

?

 

  1  
  1  
#2
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2024-10-30 12:08:16

  @GRL Yeah, i see that also. But when you turn it on, it doesn't work. I did an ARP Spoof on my network and it doesn't nothing.

 

Anyone has more information about this? Is this a bug?

  1  
  1  
#3
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2024-11-01 01:33:02

Hi @ikheetjeff 

Thanks for posting in our business forum.

ikheetjeff wrote

  @GRL Yeah, i see that also. But when you turn it on, it doesn't work. I did an ARP Spoof on my network and it doesn't nothing.

 

Anyone has more information about this? Is this a bug?

As you have verified it, then Wireshark and paste your results here which shows the router fails to perform its job.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#4
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago

any updates? my er605 does not detect any ARP attacks 

changing MAC and IP router passes and works as like nothing happened

  0  
  0  
#5
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago - last edited 2 weeks ago

  @Clive_A   

Omada er605 with firmware 2.2.6 Build 20241111 Rel.57697 doesnt detect any arp-attacks.

i can successfully assign any IP from IP-MAC Binding list for any device and it works like a charm.

 

as example no problem to assign 192.168.6.10 to any other device with different MAC  and it will work like native network device passing through all access control, policy routing and bandwitth control rules. 

 

on attacker device i successfully assigned IP that has IP-MAC binding in ARP defence: and it have access to network.

no arp-attack detected.

tell pls what wireshark log you wish to see?

  0  
  0  
#6
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago

Hi @YuriyB 

Thanks for posting in our business forum.

YuriyB wrote

  @Clive_A   

Omada er605 with firmware 2.2.6 Build 20241111 Rel.57697 doesnt detect any arp-attacks.

i can successfully assign any IP from IP-MAC Binding list for any device and it works like a charm.

 

as example no problem to assign 192.168.6.10 to any other device with different MAC  and it will work like native network device passing through all access control, policy routing and bandwitth control rules. 

 

 

on attacker device i successfully assigned IP that has IP-MAC binding in ARP defence: and it have access to network.

no arp-attack detected.

tell pls what wireshark log you wish to see?

 

 

Ends with CC:DC:3A is the device that has a 192.168.6.10 which has been taken by the entry in the ARP firewall. Right?

Filter with the ARP, and what does the router reply to the ARP?

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#7
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago - last edited 2 weeks ago

  @Clive_A  Thanks for reply.

On  windows PC with mac(E0-D5-5E-CC-DC-3A) I assigned in windows network settings static IP 192.168.6.10

 

(192.168.6.10 is another device and it has entry in ER605 ARP IP-MAC Binding List AC-80-FB-65-90-A7)

wireshark log 192168610.pcapng attached

put in ethernet cable and heres screen: 

 

No messages in syslog.

 

so any schoolboy can change his IP and making IP groups with access control list or routing rules is is senseless  :(

 

File:
192168610.zipDownload
  0  
  0  
#8
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago

Hi @YuriyB 

Thanks for posting in our business forum.

YuriyB wrote

  @Clive_A  Thanks for reply.

On  windows PC with mac(E0-D5-5E-CC-DC-3A) I assigned in windows network settings static IP 192.168.6.10

 

(192.168.6.10 is another device and it has entry in ER605 ARP IP-MAC Binding List AC-80-FB-65-90-A7)

wireshark log 192168610.pcapng attached

put in ethernet cable and heres screen: 

 

 

No messages in syslog.

 

so any schoolboy can change his IP and making IP groups with access control list or routing rules is is senseless  :(

 

This is expected behavior. You are required to enable permit the packet matching the IP-MAC Binding entries only. Or they will allow the packet forward.

 

With this option enabled, when receiving a packet, the router will check whether the IP address, MAC address and receiving interface match any of the IP-MAC Binding entries. Only the matched packets will be forwarded. This feature can be enabled only when ARP Spoofing Defense is enabled.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#9
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago - last edited 2 weeks ago

  @Clive_A Okay, now it looks like this:

 

Router tells me about suspected attack. but why it is telling arp to attacker device?

now get foreigh device, set sny IP from ARP MAC-bindig list and watching wideos from my ip cameras on foreign device. 

can access all my network devices also.

I can understand purpose of ARP-Spoofing defence?

why on tplink archer ax23 or archer c64 devices NOT from ip-mac binding list or changing IP as i did, cant access to network but er605  does?

  0  
  0  
#10
Options
Re:Why does no router support ARP Spoofing Defense in Controller mode?
2 weeks ago

Hi @YuriyB 

Thanks for posting in our business forum.

YuriyB wrote

  @Clive_A Okay, now it looks like this:

 

 

Router tells me about suspected attack. but why it is telling arp to attacker device?

 

now get foreigh device, set sny IP from ARP MAC-bindig list and watching wideos from my ip cameras on foreign device. 

can access all my network devices also.

I can understand purpose of ARP-Spoofing defence?

why on tplink archer ax23 or archer c64 devices NOT from ip-mac binding list or changing IP as i did, cant access to network but er605  does?

What indicates that the router is telling the attacker device? I don't see how you verified this.

 

sny?? What?

 

I don't understand the rest of the description. Try to use some grammar tools to address it. It does not accurately speak what you want to say.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#11
Options