Community discussions

MikroTik App
 
whitbread
Member Candidate
Member Candidate
Topic Author
Posts: 119
Joined: Fri Nov 08, 2013 9:55 pm

"ARP" Security on CRS and RB2011 using HW offloading

Tue Jan 30, 2018 12:57 pm

My network is built primarily by a CRS125 working as a switch only, a LAN firewall and a gateway router (both RB2011's).
The routers are connected thru trunked ports as I am using numerous VLAN's.
All devices are on version 6.41 and I am using the new hardware offloading, both on CRS and on RB2011s.
I do not use VLAN aware Bridges as these would intercept HW offloading.

Following the hints to secure my devices I tried to set ARP to "reply only" while adding DHCP leases to ARP.
As I did not see any effect on that change, I even disabled ARP on all interfaces on the way from device A (VLAN / subnet 10) to device B (VLAN / subnet 20) without any effect.
From my understanding ARP does not come into play on the CRS as L2 matching is done within the switch chip. The same has to be said on the switching part on the routers. But as soon as traffic leaves the switch thru any VLAN interface I expected that ARP resolution would be neccessary. But my observation is that even with disabled ARP all connection works as before.

So can someone please try to explain where ARP comes into play on a router using HW offloading?
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: "ARP" Security on CRS and RB2011 using HW offloading

Tue Jan 30, 2018 1:36 pm

Arp will be used for all connections originating at the router.
So if router tries to connect to other machine on connected network, if it doesn't have it's mac in cache/table, it will ask.

Packets from source ip coming into router are used for table update.
 
whitbread
Member Candidate
Member Candidate
Topic Author
Posts: 119
Joined: Fri Nov 08, 2013 9:55 pm

Re: "ARP" Security on CRS and RB2011 using HW offloading

Wed Jan 31, 2018 12:15 pm

Thx for your answer - it explains the connection between router and device A, but what about the connection between device A and B?

Where is ARP needed or where can I set ARP to reply-only to enhance security?

I try to draw it here:
device A (edge port; vlan10)                      vlan10 interface - Bridge10
                \                                      / 
                  CRS (trunk port*) = (trunk port*) RB2011
                /                                      \ 
device B (edge port; vlan20)                      vlan20 interface - Bridge20

* trunk ports on CRS and RB2011 are both slaves to universal bridge with activated and running HW offloading.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: "ARP" Security on CRS and RB2011 using HW offloading

Wed Jan 31, 2018 10:05 pm

connection dev A -> dev B: packets need to be forwarded by router
A -> router: mac learned from packet
router -> B: mac of B needed, if not present in cache, and discovery disabled (only reply) won't know where to send to -> failure


BTW: vlan filtering is not in hardware on crs1x

Who is online

Users browsing this forum: No registered users and 62 guests