Yo Joe! On Mon, 23 Sep 2002, Joe Touch wrote: > > root has no problem seeing adjacent UDP even on a switch. Just > >overflow the arp cache or poison it. > > That all presumes the switch doesn't detect this as an attack and > shutdown that link, which is an entirely reasonable reaction. resonable yes, practical, no. The only way I know to prevent this is to hard code the MACs on the switch. This is time consuming to install and to maintain. Barring that, please name ONE switch, or cite ONE credible reference source, where arpspoofing is prevented at the switch by any means short of harcoding the MACs. RGDS GARY --------------------------------------------------------------------------- Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701 gem@rellim.com Tel:+1(541)382-8588 Fax: +1(541)382-8676