User`s manual
Multi-WAN VPN QoS Router
236
is constantly notified with the series of error IP or if there is cheat by fake gateway, then the issue
of disconnection will affect a great number of devices. This is the typical ARP attack. It is very
easy to judge if there is ARP attack. Once users find the PC point where there is problem, users
may enter the DOS system to conduct operation, pining the LAN IP to see the packet loss. Enter
the ping 192.168.1.1 (Gateway IP address) as illustrated.
If there are cases of packet loss of the ping LAN IP and lf later there is connection, it is
possible that the system is attacked by ARP. To verify the situation, we may judge by checking
ARP table. Enter the ARP -a command as illustrated below.
It is found that the IP of 192.168.1.1 and 192.168.252 points to the same MAC address as
00-0f-3d-83-74-28. Evidently, this is a cheat by ARP.
3. ARP Solution
Now we understand ARP, ARP cheat and attack, as well as how to identify this type of attack.
What comes next is to find out effective prevention measures to stop the network from being
attacked. The general solution provided by Qno can be divided into the following three options:
a) Enable “Prevent ARP Virus Attack”:
Enter the device IP address to log in the management webpage of the device.
Enter ‖Firewall-> General‖ and find the option "Prevent ARP Virus Attack" to the right of the page.
Click on the option to activate it and click "Apply" at the bottom of the page (see illustrated).