• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Two MAC address on LAN interface

Scheduled Pinned Locked Moved General pfSense Questions
arpmac
6 Posts 4 Posters 987 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mailk
    last edited by Jun 17, 2021, 9:05 AM

    Hello!

    My antivirus started detecting ARP poisoning attacks on my pfsense LAN ip address.
    10.1.2.250 [4c:52:62:2b:57:6d];10.1.2.250 [00:00:5e:00:01:0c];

    The real interface MAC address is 4c:52:62:2b:57:6d.
    I dont know where the 00:00:5e:00:01:0c address is comming from.

    I checked the host table of the switch that is directrly connected to the pfsense box and the switch sees this 00:00:5e:00:01:0c adress on the interface it is connected to the pfsense box.
    The switch also sees the real MAC address on that interface too.

    I cant find this second MAC adress anywhere in pfsense.

    Any clue?
    Thanks.

    J 1 Reply Last reply Jun 17, 2021, 10:18 AM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @mailk
      last edited by johnpoz Jun 17, 2021, 10:21 AM Jun 17, 2021, 10:18 AM

      @mailk said in Two MAC address on LAN interface:

      00:00:5e:00:01:0c

      That is a carp address mac with vhid 12..

      So your running pfsense in HA, or you tried to set it up? You setup a carp vip?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply Jun 17, 2021, 10:37 AM Reply Quote 0
      • M
        mailk @johnpoz
        last edited by Jun 17, 2021, 10:37 AM

        @johnpoz
        Yes, its a CARP vip address, it is like that from the begining, sorry i forgot to mention it.
        Now i can see in the documentation that it gets a unique MAC basd on the VHID.

        The question is, why did the AV started to alert about it now?

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Jun 17, 2021, 12:53 PM

          I assume 10.1.2.250 is the CARP IP not the interface IP?

          If so that's how it has always worked. You would need to ask your antivirus vendor why it is now flagging that.

          Steve

          1 Reply Last reply Reply Quote 0
          • M
            mailk
            last edited by Jun 17, 2021, 1:05 PM

            The problem has been resolved.
            I just needed to flush the ARP table on the client computers.
            Somehow the phisical interface MAC (4c:52:62:2b:57:6d) was in their table not the "CARP MAC" (00:00:5e:00:01:0c).
            Thats why the AV was fustrated.

            Thanks for the comments!

            1 Reply Last reply Reply Quote 0
            • F
              funtiklugin
              last edited by Feb 27, 2025, 2:58 PM

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received