The idea seems sound but just one problem and I think ISP know too and the bad way they are dealing with it. I posted about ISP doing NAT when some of us want are WAN IP.
So like I'm with virgin media with lets say a IP of 92.239.64.2 If some how I was to send from the same MAC source IP 4.79.142.200 to target thats what you want to block but nothing is stopping attackers from using other IP in the same subnet like 92.239.64.222 and to a ISP that would look valid but really coming from 92.239.64.2.
So how do you deal with that? Well ISP taking the dirty way out by them doing NAT that stops spoofing the real solution is DAI (Dynamic ARP Inspection) on the modem but it seems ISP want the cheapest way out and so NAT...doubt NAT..I hate.
So like I'm with virgin media with lets say a IP of 92.239.64.2 If some how I was to send from the same MAC source IP 4.79.142.200 to target thats what you want to block but nothing is stopping attackers from using other IP in the same subnet like 92.239.64.222 and to a ISP that would look valid but really coming from 92.239.64.2.
So how do you deal with that? Well ISP taking the dirty way out by them doing NAT that stops spoofing the real solution is DAI (Dynamic ARP Inspection) on the modem but it seems ISP want the cheapest way out and so NAT...doubt NAT..I hate.
