Re: Solaris ARP bug?

From: Barry Margolin (barmar_at_alum.mit.edu)
Date: 02/03/04


Date: Tue, 03 Feb 2004 03:25:27 GMT

In article <20ATb.168032$nt4.752197@attbi_s51>,
 Michael Steele <michael+nospam@netsteele.com> wrote:

> As far as I know, the Ethernet specification requires that when a host
> sends an ARP RESPONSE, all hosts listening on that wire should cache the
> entry.

Is ARP really covered in the Ethernet specification? Is the description
there different from RFC 826?

RFC 826 says that a host should update an *existing* ARP cache entry
when it receives any ARP packet, and should create one when it receives
an ARP query for itself.

Sun has gone beyond this, caching all ARP information that it receives.
However, information from unsolicited messages has a shorter timeout, so
that they won't overflow the ARP cache.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***


Relevant Pages

  • mac address issue
    ... I'm seeing two different mac addresses ... it's arp cache, but the switch plugged into that port doesn't. ...
    (Security-Basics)
  • Re: switch jamming
    ... > There are two widely-understood ways to make a switch send traffic your ... The other is to poison the ARP cache of one or more ... > that people are referring to the MAC address cache rollover attack ...
    (Vuln-Dev)
  • Re: Replacing a PIX 515E with a PIX 515
    ... She recommended that we reset the ARP ... After looking at the ARP cache on our router, ...
    (comp.dcom.sys.cisco)
  • Re: Any reasons to filter ARP packets?
    ... but maybe clear the cache (using the 'arp' command). ... Are they comming from the gateway MAC and out-site IP adresses? ... I don't observe any connection attempts any more. ...
    (comp.os.linux.security)
  • Re: sygate and shields up
    ... ARP table) the router will have an ARP entry. ... ARP request (which would result in the router responding as in your ...
    (comp.security.firewalls)