DWS-3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide
942
Figure 5
Likewise, the attacker can either choose to forward the traffic to the actual default gateway
(passive sniffing) or modify the data before forwarding it (man-in-the-middle attack).
The hacker cheats the victim PC that it is a router and cheats the router that it is the victim. As can
be seen in Figure 5 all traffic will be then sniffed by the hacker but the users will not discover.
Prevent ARP Spoofing via Packet Content ACL
D-Link managed switches can effectively mitigate common DoS attacks caused by ARP spoofing
via a unique Package Content ACL.
For the reason that basic ACL can only filter ARP packets based on packet type, VLAN ID, Source,
and Destination MAC information, there is a need for further inspections of ARP packets. To