---
title: ARP Security Controls: 2 Checks | Wartiva
description: The 2 checks Wartiva runs for ARP, beyond the CIS Benchmarks: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva/arp.html
updated: 2026-10-07
---

Wartiva Security Controls

# ARP: 2 Checks

Wartiva's ARP controls: conflicting ARP table entries and ARP spoofing of the default gateway on the endpoint's local network segment.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## The endpoint's ARP table contents

### [Ensure No Conflicting ARP Table Entries Are Present](https://wartiva.com/policy-rules/wartiva/arp.html#no-conflicting-arp-table-entries-are-present)

Low severity · Wartiva Security Controls · ARP

**Finding:** This IP address is claimed by more than one MAC address (ARP conflict).

This rule inspects a single ARP/neighbor cache entry. This rule fails when the entry's IP address is currently claimed by one or more other MAC (hardware) addresses on the same interface.

The conflicting entries are recorded on the entry itself as the endpoint's ARP table is collected, so the check reads only this entry. Conflicts are scoped per interface: a multi-homed host legitimately resolves the same private address to different hardware on different segments, and that is not a conflict.

**Rationale:** An IP address should resolve to exactly one hardware address on a given segment. Two MACs claiming one IP is either a duplicate-IP misconfiguration or the signature of ARP spoofing, in which an attacker injects forged ARP replies to redirect traffic.

**Impact:** Duplicate mappings cause intermittent connectivity loss and, when malicious, allow an attacker on the local segment to intercept or manipulate the victim's traffic.

#### Remediation

Investigate the duplicate IP-to-MAC mappings. Confirm whether two devices are misconfigured with the same IP address or whether one MAC is impersonating another (ARP spoofing). Reconcile DHCP reservations, correct any duplicate static IP assignments, and if impersonation is suspected, isolate the offending device and report it to your security team.

Risk

Reliability Impact

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Evidence of ARP spoofing on the local segment

### [Ensure The Default Gateway Is Not Being ARP Spoofed](https://wartiva.com/policy-rules/wartiva/arp.html#the-default-gateway-is-not-being-arp-spoofed)

Critical severity · Wartiva Security Controls · ARP

**Finding:** The default gateway's IP address is claimed by more than one MAC address (possible ARP spoofing).

This rule finds ARP table entries for a device acting as a network gateway whose IP address another entry on the same endpoint and interface claims with a different MAC address. This rule fails for each such entry.

**Rationale:** In an ARP-poisoning (gateway-theft) attack, an adversary forges ARP replies so that the gateway's IP maps to the attacker's MAC, putting the attacker in the path of all off-subnet traffic. A gateway address claimed by more than one hardware address means the legitimate gateway and an impersonator are both present.

**Impact:** An attacker who spoofs the gateway can intercept, modify, or drop all traffic leaving the local network (adversary-in-the-middle), enabling credential theft and data exposure.

**Note:** This detects the contested state. A cache in which the attacker has fully overwritten the gateway entry with a single MAC is not detected here.

#### Remediation

Treat this as a potential man-in-the-middle attack on the default gateway. Verify the correct hardware address of your gateway or router, then remove or block the impersonating device from the network. On managed switches, enable Dynamic ARP Inspection (DAI) and DHCP snooping, and consider a static ARP entry for the gateway on critical hosts. Report the incident to your security team.

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
