For ARP spoofing on a shared segment, what do static ARP entries and private-VLAN port isolation each stop, and what does each cost to operate?
answer
- pin the mapping or cut the path
- one side protected only
- who can talk to whom
- upkeep when hardware changes
basics
~20 sA static entry pins one host's mapping against forged packets but protects only that host and needs editing when a MAC changes. Port isolation stops peers reaching each other at Layer 2, containing poisoning but not the path to the gateway.
solid answer
~40 sA static ARP entry is set by an administrator and, on most implementations, is not overwritten by ARP packets. That protects the host holding it, for example a server's entry for its gateway, but costs a manual edit whenever a NIC or address changes, and it does not protect the gateway's entry for the server. RFC 5517 describes private VLANs, where isolated ports cannot talk to each other, only to promiscuous ports; §6 names containing ARP poisoning as a use. That blocks host-to-host poisoning, but an attacker on an isolated port can still reach the gateway on the promiscuous port. Both are partial; switch-side inspection is the general control.
go deeper
Know that a static ARP entry is a manually set mapping that forged packets should not change, but it must be maintained.
Explain that static entries protect one side, and that private-VLAN isolated ports cannot reach each other, limiting poisoning between hosts.
Say where each leaves a gap - the gateway's table, the promiscuous port - and combine them with binding-based inspection rather than relying on any one.
Choose where per-host pinning is worth its upkeep and where segmentation is the cheaper control, and say who owns the exceptions.
## Two different ideas **Static entries** make the mapping immune to packets. **Port isolation** limits who can send packets to whom. Neither authenticates ARP, and each leaves a gap you must name in an interview. ## Static ARP entries An administrator creates the IP-to-MAC mapping by hand. RFC 826 defines no timeout, and RFC 1122 §2.3.2.1 requires a way to flush out-of-date dynamic entries; static entries sit outside that process. Whether an incoming ARP packet may overwrite a static entry is an **implementation property**, and on common systems it may not. - **Good for** a small number of high-value pairs: a server's entry for its gateway, a gateway's entry for a management host. - **Costs:** 1. Every NIC replacement, failover to different hardware or address change needs a manual edit on every host that holds the entry. 2. The number of entries grows with the number of host pairs, so it does not scale to a whole segment. 3. The protection is **one-sided**: it covers only the host that has the entry. If the gateway's cache for the server is still dynamic, a forged packet can redirect the gateway-to-server direction. 4. Static entries are invisible to people who do not look, which makes a stale one a confusing outage. ## Port isolation with private VLANs RFC 5517 (Informational, a description of an existing design) defines three port types in a private VLAN domain: | Port type | Can talk to | |---|---| | Promiscuous | All other ports in the domain | | Isolated | Only promiscuous ports, not other isolated ports | | Community | Its own community and promiscuous ports | Hosts on isolated ports cannot exchange Layer 2 frames, so one cannot send forged ARP packets to another. §6 of that RFC says private VLANs can be used to block or contain unwanted inter-device communication such as port scans or ARP poisoning attacks. - **Good for** shared networks of mutually untrusting tenants or kiosk-style hosts that only need the gateway. - **Costs:** legitimate peer-to-peer traffic must go through a router or firewall on the promiscuous port; community and trunk configuration add complexity; the gateway sits on a promiscuous port. - **Gap:** an isolated host can still send ARP to the promiscuous port, so a forged claim to the gateway for another host's IP remains possible, and the gateway's entry for that victim is what is poisoned. That is half of a man-in-the-middle, not none of it. ## How they compare with switch-side inspection | Control | Protects | Main weakness | |---|---|---| | Static entries | The holder's own entries | Scale and upkeep; one-sided | | Port isolation | Host-to-host Layer 2 reach | Gateway still reachable; breaks peer traffic | | Inspection against bindings | All hosts on inspected ports | Needs a complete, honest binding table | SAVI, in RFC 7039 and RFC 7513, is the IETF's general approach to source-address validation, and its ARP rule is the standards-track counterpart of switch inspection. ## Interview summary Say that static entries and isolation are **targeted mitigations**: pin the few critical mappings, isolate hosts that do not need each other, and rely on binding-based inspection for the segment. Mention that segmentation design and port admission are owned by other topics, and that none of these helps against an attacker you have already admitted to a trusted position.
- A server has a static ARP entry for its gateway; what can an attacker still do to its traffic?Poison the gateway's dynamic entry for the server. Frames from the gateway to the server then reach the attacker, while the server's outbound frames are safe. The server's static entry protects only its own table. Defenders would pin both sides or validate ARP at the switch.
- Why does isolating ports not fully remove ARP spoofing risk?An isolated host can still send frames to the promiscuous port where the gateway sits. A forged ARP claim aimed at the gateway for another host's IP can still mislead the gateway, so isolation reduces the attack surface rather than closing it.
saying these in an interview costs you the question
- Says static entries protect both directions of a conversation
- Believes private VLANs authenticate ARP packets
- Thinks static entries scale to a whole office segment
- Treats isolation as a complete fix for gateway poisoning
- Assumes every OS refuses to overwrite a static entry