[nsp] Code red and ARPs

From: Hank Nussbacher (hank@att.net.il)
Date: Tue Aug 07 2001 - 06:55:26 EDT


I am seeing more and more incomplete entries in my arp tables resulting
from Code Red scans:

Protocol Address Age (min) Hardware Addr Type Interface
Internet 192.116.94.68 0 Incomplete ARPA
Internet 192.116.94.69 0 Incomplete ARPA
Internet 192.116.94.91 0 Incomplete ARPA
Internet 192.116.94.95 0 Incomplete ARPA
Internet 192.116.177.178 0 Incomplete ARPA
Internet 192.116.94.82 0 Incomplete ARPA
Internet 192.116.94.84 0 Incomplete ARPA
Internet 192.116.94.42 0 Incomplete ARPA
Internet 192.116.94.43 0 Incomplete ARPA
Internet 192.116.94.40 0 Incomplete ARPA
Internet 192.116.94.41 0 Incomplete ARPA
Internet 192.116.94.46 0 Incomplete ARPA
Internet 192.116.94.47 0 Incomplete ARPA
Internet 192.116.94.44 0 Incomplete ARPA
[very partial list]

"clear arp-cache" doesn't help and there appears to be no way to set a
timer to get rid of these entries (arp timers are only on a per interface
basis and not for incompletes). Anyone else see this and have a solution?

-Hank



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:48 EDT