Administrators face a challenge with few technical users in their organization who can try to stop the Internet usage for other users by using a software which can proxy the mac address of other user's system. The main purpose is to increase the bandwidth usage per ip by stopping the Internet traffic for few users.
One such software is Netcut from Arcai vendor who has released app for iOS and Android as well now.
These softwares or applications can proxy the mac address list of any system in the local networks thereby manipulating with router's or firewall's ARP table.
Notice the ARP table of the SonicWall before and after running the software :
Running packet capture on the firewall will show that firewall will send the traffic response to that dummy mac address, instead of original mac address after using that software :
To prevent this, SonicWall has an option of MacAntiSpoof which can be configured as following to block the software :
Navigate to Manage |System Setup | Nnetwork | Mac-IP Anti-Spoof.
Select the local interface from where the user is using the software.
Under Anti-spoof settings, select the option Enable MAC-IP based anti-spoofing and'DHCP SERVER - Populate MAC-IP anti-spoof entry from DHCP Lease.
Under ARP settings, select the option ARP Lock - Lock MAC-IP binding in ARP cache to prevent ARP poisoning from others.