Gateway keeps flooding the network with arp requests

asked 2018-01-12

rgb89 gravatar image

I have a small home network consisting of the gateway from the ISP, and less than 15 wireless clients. I noticed the network slowed down alot, even when there was only 1 client connected. I downloaded wireshark and captured with only 1 pc connected via ethernet, disabled the wifi and disconnected the telephone line that feeds the gate way. Every few seconds, i see the gateway sending out arp requests to sequential ip addresses that dont even exist on the network. See the image and file below. Capture: Capture file:

Im sure this is not normal behavior. There is alot of lag on the network at the moment its hard to get any work done.What could be causing this? Is it possible for the gate to be poisoned in this way? Any guidance provided would be greatly appreciated. Thank you!

answered 2018-01-12

sindy gravatar image

By itself, 100 arp requests every 5 seconds can not cause any network lag. What causes the router do that, and what happens if it gets a response, is a much more important question.

Is it possible for the gate to be poisoned in this way?

The sad answer is yes, home gateways can get infected by malware, with vulnerabilities ranging from vendor's backdoors through default WiFi passphrases deductible from MAC address which is broadcasted in the beacon frames combined with easy administrator passwords used "because the WPA2 is unbreakable so who cares about admin password" down to management ports open at WAN interface. Also an infected PC in the home LAN can silently keep trying to log as administrator to the gateway router using vocabularies of popular passwords.

So if re-flashing the router firmware, using TFTP during boot if supported in order to minimize chances for survival of the malware, helps, there is a high probability that your box got exploited.

Asked: 2018-01-12

Last updated: Jan 12