- Posts: 19
- Thank you received: 0
Unicast ARP
15 years 9 months ago #30110
by RA1313IT
Unicast ARP was created by RA1313IT
I recently was looking at some packet captures on my network when I realized something that seemed a bit strange to me. There was Linux machines (namely Ubuntu) that were sending ARP requests for machines and the frames had a destination MAC address of the actual machine. I checked the ARP cache on these machines and they of course had the correct MAC address in it's cache.
I was always taught and under the impression that ARP requests were always broadcast (destination FF:FF:FF:FF:FF:FF) It is as if since the machines had it's MAC address cached, it would not broadcast these frames unless the ARP cache was cleared. I verified this by deleting the ARP entry, and I viewed the first ARP request as broadcast, and subsequent ones unicast.
I guess this makes sense to reduce broadcast traffic, and it may be something that only Linux incorporates. Does anyone know the source of this behavior?
I was always taught and under the impression that ARP requests were always broadcast (destination FF:FF:FF:FF:FF:FF) It is as if since the machines had it's MAC address cached, it would not broadcast these frames unless the ARP cache was cleared. I verified this by deleting the ARP entry, and I viewed the first ARP request as broadcast, and subsequent ones unicast.
I guess this makes sense to reduce broadcast traffic, and it may be something that only Linux incorporates. Does anyone know the source of this behavior?
15 years 9 months ago #30112
by S0lo
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
Replied by S0lo on topic Re: Unicast ARP
Interesting, It indeed seams that some implementation of linux do that, although I'm not sure here.
insecure.org/sploits/arp.games.html
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
Time to create page: 0.125 seconds