cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2931
Views
10
Helpful
4
Replies

ARP Poisoning detection with FTD

Neophyte
Level 1
Level 1

I'm new to dealing with the FMC and FTD, and new to working directly with Cisco Products in general, but I'm wondering if anyone could point me in the right direction regarding detection for ARP Poisoning from the FTD appliance.

 

So far, I have tried to create a Correlation Rule, which did not work in detecting ARP Poisoning. I have also discovered that the underlying IDS of the FTD is Snort, which does have a preprocessor for detecting ARP Poisoning, however, I cannot see it within the list of preprocessors. I have also noticed some ARP Poison related signatures in the "DELETED" folder in Intrusion Rules.

Basically my questions are:

  1. Is there a way to upgrade the FMC to include more of the preprocessors that come with Snort?
  2. How do you go about moving something from the "DELETED" folder back into the main Intrusion Rule folders.
  3. Failing being able to accomplish either of these, is there another method to go about detecting ARP Poisoning with the FMC/FTD?

Any and all help will be much appreciated! 

4 Replies 4

Hi,

If FTD in routed mode it can not detect arp poisoning. For arp poisoning,
you need DAI feature on the switches along with dhcp snooping.

****** please remember to rate useful posts

Hi Mohammed,

 

Thank you for the response!

 

So are you saying that the FTD appliance needs to be in Transparent mode and then I would also need to set up the DAI feature on the switches along with DHCP Snooping to make ARP Poisoning detectable within the FMC? Or are the DAI and DHCP Snooping features just a mitigation technique?

 

Cheers.

If you use dai then no need to do anything on firepower. If you don't want
to use dai then option B is firepower in transparent mode.

I strongly recommend to use dai its straight forward and well implemented
by the switches. Also generate relevant syslogs.

**** please remember to rate useful posts

Thank you for you help Mohammed!

Review Cisco Networking for a $25 gift card