- status: open --> closed
Running the Ubuntu arpon 3.0-ng+dfsg1-1, we see query floods from arpON in apparently in response to ARP announcments from the same machine. See the attached Wireshark trace for an example. The trace is from another machine on the same network, and is filtered to just show ARP. The machine running ArpON is the one with the one with the Belkin MAC address.
I tried a number of things from another machine to attempt to reproduce this reliably. I used nemesis https://github.com/libnet/nemesis to send ARP announcements for an IP which no machine was actually using. ArpON responds with the usual "who-has" for that IP and receives no response. I announced the the ArpON machine's own LAN IP. I announced the IP of something which exists (and so will respond to ArpON's who-has) repeatedly. None of this were sufficient alone to provoke the floods, but we do see them fairly regularly.