NET0781 - Gratuitous ARP must be disabled.

Information

The router must have gratuitous ARP disabled.

A gratuitous ARP is an ARP broadcast in which the source and destination MAC addresses are the same. It is used to inform the network about a hosts IP address. A spoofed gratuitous ARP message can cause network mapping information to be stored incorrectly, causing network malfunction. Review the configuration and verify that the 'ip gratuitous-arps' global command is not configured. It is disabled by default in release 12.3 and above.

Solution

The administrator must ensure the device configuration does not include the 'ip gratuitous-arp' command.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R28_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CAT|II, Rule-ID|SV-5618r3_rule, STIG-ID|NET0781, Vuln-ID|V-5618

Plugin: Cisco

Control ID: 6cc1edd85fc0cbea9a46cd8de6185b1d2f4b8c2e4265af327a747dddafb6b088