Community discussions

MikroTik App
 
network99
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Wed Nov 22, 2017 8:47 pm

ARP Table is 00:00:00:00:00:00

Mon Feb 19, 2018 11:44 am

Hi all

i use RouterBOARD 941-2nD for Local Network
my mac table is full of 00:00:00:00:00:00 MAC addresses ,
where is the problem from ?
Has my router been hacked?


Image
 
User avatar
acruhl
Member
Member
Posts: 371
Joined: Fri Jul 03, 2015 7:22 pm

Re: ARP Table is 00:00:00:00:00:00

Mon Feb 19, 2018 6:33 pm

Possibly. I'm trying to think of a legit use of all zeroes as a MAC and I don't know of one. Hopefully someone knows.

To me that looks like some kind of a DDoS attack on that subnet. I would sniff it. If a machine is sending out gratuitous arps with all zeroes for all addresses in the subnet, then you found the problem.

Seems likely to me that it's one machine that's doing that.
 
network99
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Wed Nov 22, 2017 8:47 pm

Re: ARP Table is 00:00:00:00:00:00

Mon Feb 19, 2018 8:11 pm

Possibly. I'm trying to think of a legit use of all zeroes as a MAC and I don't know of one. Hopefully someone knows.

To me that looks like some kind of a DDoS attack on that subnet. I would sniff it. If a machine is sending out gratuitous arps with all zeroes for all addresses in the subnet, then you found the problem.

Seems likely to me that it's one machine that's doing that.
thank a lot

how block this attack ?
 
pe1chl
Forum Guru
Forum Guru
Posts: 10511
Joined: Mon Jun 08, 2015 12:09 pm

Re: ARP Table is 00:00:00:00:00:00

Mon Feb 19, 2018 9:33 pm

It is not a problem. You can ignore this.
Only when the left column would show DC instead of D it would be a problem!
 
User avatar
acruhl
Member
Member
Posts: 371
Joined: Fri Jul 03, 2015 7:22 pm

Re: ARP Table is 00:00:00:00:00:00

Tue Feb 20, 2018 7:55 am

Have you seen this before? What is doing that?

I didn't pick up on the D vs DC, good call.

Still, it seems like a single machine trolling the subnet space for something... It's annoying if nothing else.

If this was my network I would be looking at packet sniffer traces to see what is doing this and why. The answer might not be malicious but it's not polite.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10511
Joined: Mon Jun 08, 2015 12:09 pm

Re: ARP Table is 00:00:00:00:00:00

Tue Feb 20, 2018 10:52 am

Depending on RouterOS version (which he does not reveal) the situation of a pending ARP entry is either
not displayed at all, displayed as blanks, or displayed as 00:00:00:00:00:00
Apparently the latter in his case.
Something is scanning the network causing the router to ARP to all addresses, and there is apparently nothing
on those addresses so you see the result shown in the screenshot.

You are right, it would be a good idea to check what is doing this and if this is normal.
But it is not a fault of the MikroTik. Well, that is not completely excluded: the same thing is shown during
or just after use of the function tools->IP scan.

Who is online

Users browsing this forum: benonet, Bing [Bot] and 20 guests