Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Change default gateway ip out of your pool range to disable arp poison

    DHCP and DNS
    4
    5
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mohandshamada
      last edited by

      hellow guys,

      I tried to change the default gate way in lan side to prevent arp poison programm such as netcut to work

      note: in pfsense here you can't change your default gateway in dhcp server with ip differ from your pool range so here is the tutorials

      1- first got to firewall>>virtual ip  and add new virtual ip

      2- choose IP Alias and choose lan and enter your fake ip then save & apply changes

      3- go to services >> dhcp server and enter in the default gateway your fake ip you created before and save

      it will accept the ip

      any one can try and return back with the result

      1 Reply Last reply Reply Quote 0
      • P
        P3R
        last edited by

        @mohandshamada:

        I tried to change the default gate way in lan side to prevent arp poison programm such as netcut to work

        Can you please explain how that prevention works?

        1 Reply Last reply Reply Quote 0
        • M
          mohandshamada
          last edited by

          @P3R:

          @mohandshamada:

          I tried to change the default gate way in lan side to prevent arp poison programm such as netcut to work

          Can you please explain how that prevention works?

          it send to the client the fake gate way so when the netcut search will not find the real gate way to poison

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            I don't see how this is going to prevent arp poisoning.
            The alias you created has the same MAC address as the real gateway.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • S
              Supermule Banned
              last edited by

              Maybe option to spoof MAC in VIP could be an option??

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.