Network Security - Ensure Proxy ARP is either not configured, or is restricted to specific interfaces

Information

Proxy ARP (Address Resolution Protocol) is a technique where a networked device, usually the router, will answer an ARP request for another device. At that point the router is responsible for routing the packet to the destination.

Proxy ARP could potentially be used by a malicious user in an attempt to put unnecessary load on the Routing Engine. Another side effect of proxy ARP is that it masks configuration errors, such as incorrect subnet masks that can cause network outages.

Solution

Review the configuration and verify that if 'proxy-arp' is configured, that is is configured as 'proxy-arp restricted'.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Juniper

Control ID: ed4eb51ad27b3e7b2077294165d7ebc566ebbd72f698ee0354a21c134257c4c8