-
arpwatch flipflop
Hi all,
I get some chaotic arpwatch flipflop.
Sometimes very few 4 a day some time huge amount 100 or 200 a day.
Each time I get them by 2 copies :
Or when server's MAC address is involved I've got :
and
I get only this on the External IP address
that raise some alert on my ISP router :
NIC 0c:c4:7a:33:07:8b and 0c:c4:7a:33:07:8a use the same IP address 10.0.0.142
But in this message this is the LAN IP that is involved
I've got 2 NIC :
enp4s0 External Static 10.0.0.137
enp3s0 LAN Static 10.0.0.142
The strange thing is that the mac adress in the arpwatch alert email could be anything :
from the 2 server NIC MAC address
2 other equipement MAC Address
In the exemple this is my ISP router MAC Address and my laptop and then my ISP router and my PC
I need my network to work with or without the ClearOS server on. I do not use firwall feature of the Clear OS.
Any idea of the reason for that ? -