Protection Against a Gratuitous ARP Attack
Devices have the capability to send Address Resolution Protocol (ARP) packets irrespective of whether they are responding to an ARP request. These ARP messages have the potential to corrupt the ARP table on the ICX devices and exhaust the MAC table. This can lead to legitimate ARP reply packets being rejected.
The transmission of gratuitous ARP packets by a device could potentially facilitate an ARP Cache Poisoning and Man-in-the-Middle attacks. We can address these attacks using the ARP MAC source address mismatch feature. This feature involves comparing the source address in the MAC header with the sender hardware address in the ARP payload. In the event of a mismatch, the ARP packet may be considered malicious and either sent to the CPU or dropped.
The ARP packets that are supposed to be dropped can also be captured by the CPU to share statistics and for analysis. This information includes the source MAC address of the packet and the count. This CPU capture can be enabled for a few seconds and only if ARP analysis is enabled. Dropping of gratuitous ARP packets is configured at global configuration level and does not use any space in the TCAM.