I Think This Is My Favorite Firewall Command Of All Time!

Layer 2 – Ethernet Frames – Leet ARP Spoofing

ebtables -t nat -I PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-src 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROP
ebtables -t nat -A PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-dst 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROP

~

Layer 3 – Second Favorites – Lazy DHCP Snooping

ebtables -t nat -I PREROUTING -i eth0.1 -p IPv4 --ip-proto udp --ip-sport 67 -j ACCEPT
ebtables -t nat -A PREROUTING -i wifi+ -p IPv4 --ip-proto udp --ip-sport 67 -j DROP

~

[kmod-nft-bridge]

table bridge ethernet {
chain PREROUTING {
type filter hook prerouting priority filter; policy accept;
iifname "wifi*" arp operation reply arp saddr ether != 00:11:22:33:44:00 arp saddr ip 192.168.1.1 counter drop
iifname "wifi*" ip protocol udp udp sport 67 counter drop
}
}

~

OpenWRT Config

wireless.default_radio0.isolate='1'
wireless.default_radio0.bridge_isolate='1'

~

Untested Commands

bridge link set dev wlan0 hairpin off isolated on
ebtables -A FORWARD -i wlan0 -o wlan0 -j DROP

~

Note: Most of these commands won’t work on UAP-U7-PRO APs I believe due to hardware based frame/packet routing/forwarding – I have since enabled arp-proxy and dhcp-snooping in the UI network controller application, however, I don’t see them working either, possibly because I am running a third-party gateway device. I have finally enabled client-isolation, which as tested, solves the ARP and DHCP attacks completely and forces client-to-client communication through the router instead for even further filtering!

~

Leave a comment