Layer 2 – Ethernet Frames – Leet ARP Spoofing
ebtables -t nat -I PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-src 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROPebtables -t nat -A PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-dst 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROP
~
Layer 3 – Second Favorites – Lazy DHCP Snooping
ebtables -t nat -I PREROUTING -i eth0.1 -p IPv4 --ip-proto udp --ip-sport 67 -j ACCEPTebtables -t nat -A PREROUTING -i wifi+ -p IPv4 --ip-proto udp --ip-sport 67 -j DROP
~
[kmod-nft-bridge]
table bridge ethernet { chain PREROUTING { type filter hook prerouting priority filter; policy accept; iifname "wifi*" arp operation reply arp saddr ether != 00:11:22:33:44:00 arp saddr ip 192.168.1.1 counter drop iifname "wifi*" ip protocol udp udp sport 67 counter drop }}
~
OpenWRT Config
wireless.default_radio0.isolate='1'wireless.default_radio0.bridge_isolate='1'
~
Untested Commands
bridge link set dev wlan0 hairpin off isolated onebtables -A FORWARD -i wlan0 -o wlan0 -j DROP
~
Note: Most of these commands won’t work on UAP-U7-PRO APs I believe due to hardware based frame/packet routing/forwarding – I have since enabled arp-proxy and dhcp-snooping in the UI network controller application, however, I don’t see them working either, possibly because I am running a third-party gateway device. I have finally enabled client-isolation, which as tested, solves the ARP and DHCP attacks completely and forces client-to-client communication through the router instead for even further filtering!
~