At present, the ARP virus is so rampant that tcpdump in the LAN is able to check whether all machines on the machine are engaged in ARP attacks (some are intentional, some are poisoned when Internet access through shared bandwidth ), the vro does not support binding the Client IP address to the MAC address, which is suffering from the ARP virus. We will provide anti-virus experience for your reference. The principle of ARP virus is similar to the situation where the gateway and the MAC address and IP address of the attacked machine are bound. If you do not have control over the vro or the vro does not support binding the Client IP address to the MAC address, it is troublesome to access the Internet normally. In LinuxIt is easy to resolve the underlying symptoms. In this machine, as long as the gateway MAC address is statically bound, the gateway MAC address will not be cheated. However, to let the gateway know the MAC address of your machine, you must notify the gateway of your IP address.
Simply ping the IP address of the local machine.
Trilogy: assume that your Nic is eth0
Step 1: record the IP address and MAC address of the normal gateway when no virus attacks occur.
Step 2: The correct MAC address of the ARP-s gateway IP Gateway
# Send mac and IP binding information of the local machine to the gateway through broadcast.
Step 3: arping the IP address of the eth0 Nic of the Local Machine &
There is another way to access the Internet: Use arpscan or arping or tcpdump (the IP address of the arpscan gateway can be known) it is easy to find out the MAC address disguised by the gateway as the ARP attack (This MAC address may not actually exist), and set the MAC address of your Nic to be the same as this address to access the Internet.
These methods only allow you to access the Internet normally when you are under an ARP attack, but after all they are not a cure. The only cure is that a real person can defeat an ARP attack machine. Other methods can be used.
# Cancelling ARP response
Ifconfig eth0-ARP
Use arptables and iptables firewall tools to only allow communication between the local machine and the gateway.