WRVS4400N MAC Oscillation

Discussion in 'Cisco Small Business Routers and VPN Solutions' started by Aviator256, Feb 3, 2008.

  Aviator256

    Aviator256 LI Guru Member

    I am using Wireshark and setting the WRVS4400N external port to mirror to my internal PC port. The WRVS4400N is set up for WAN DHCP on the RCN Cable Provider Network. Every once in a while, the RCN DHCP computer will send out a "DHCP ACK" message [SrcPort:bootps(67), DstPort:bootpc(68)]. The WRVS4400N will respond to the DHCP ACK with both the internal and external MAC addresses. I believe that in the IPv4 environment (No Dual Stack IPv6), the router should only respond with the external MAC Address. I believe this is a security flaw in the WRVS4400N that allows for man in the middle attacks or DHCP spoofing. If you are wanting to use the WRVS4400N in "Paranoid" mode, the quick fix is to use a static IP address and the MAC Address oscillation should stop.
  mstombs

    mstombs Network Guru Member

    This sounds similar to the Linux debate a few years ago about the way the kernel responds to arp messages (the "hidden" patch vs proc flags). But this is dhcp so it is the dhcp client on the WRVS4400N that appears to be bugged.
