Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ARP Poisoning logging Sophos XG v18.5

I have been looking for this answer. When you turn on Log possible neighbor poisoning attempts on the Neighbors (ARP-NDP) page, into what log does this actually go and as what?

I can't see it clearly listed on https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Logs/LogFileDetails/index.html

I know that there is IP Spoof log comp in the Firewall log but I would have thought that is more related to the DoS and spoof protection in Intrusion prevention area (but correct me if I and wrong)



This thread was automatically locked due to age.
  • Sophos Firewall uses the Address Resolution Protocol (ARP) and Neighbor Discover Protocol (NDP) to enable communication between hosts residing on the same subnet. It uses these protocols to create IP/MAC mappings and stores them in neighbor caches. Static mappings are also supported. The firewall uses cached entries to detect neighbor poisoning attempts.

    KDealer Login

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?