Drop Gratuitous ARP frames on All IPv4 Interfaces
Sets net.ipv4.conf.all.drop_gratuitous_arp=1 so the kernel ignores unsolicited ARP announcements used for cache poisoning.
Checked against the resolved running state (e.g. sshd -T, sysctl, systemctl show), catches drop-ins and Includes a file read would miss. Caveat: runtime ≠ persistence; a value correct now may not survive a reboot.
Pavois asserts the effective configuration, the live, resolved state, not a file. File-based scanners (OVAL/SCAP, Lynis) miss Includes, drop-ins and runtime defaults; this check sees what is actually applied.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
Gratuitous ARP frames are unsolicited ARP announcements ("this IP is now at this MAC") that a host broadcasts without anyone asking. Because ARP is unauthenticated, an attacker can flood the segment with forged gratuitous ARP to poison neighbors' ARP caches and redirect their traffic to themselves, the core technique of ARP-spoofing man-in-the-middle attacks. Setting net.ipv4.conf.all.drop_gratuitous_arp=1 makes the kernel ignore these unsolicited announcements, neutralizing this poisoning vector. Legitimate use of gratuitous ARP (e.g. failover IP takeover) is the main thing to weigh against it.
What Pavois checks
Pavois reads the live kernel value via kernel_parameter('net.ipv4.conf.all.drop_gratuitous_arp') and asserts it equals 1. Whether gratuitous ARP is actually dropped depends on the running kernel value, not on a config file: a sysctl.d entry written but not reloaded, or overridden by a per-interface key, would leave the host still accepting poison frames. Reading the effective value is the only proof the protection is live.
describe kernel_parameter('net.ipv4.conf.all.drop_gratuitous_arp') do
its('value') { should cmp 1 }
end
describe command("grep -hsE '^[[:space:]]*net.ipv4.conf.all.drop_gratuitous_arp[[:space:]]*=[[:space:]]*1([[:space:]]|$)' /etc/sysctl.conf /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf 2>/dev/null") do
its('stdout') { should match(/\S/) }
endHow to verify it is applied
Run sysctl net.ipv4.conf.all.drop_gratuitous_arp. Expected output:
net.ipv4.conf.all.drop_gratuitous_arp = 1
Inspect & investigate
sysctl net.ipv4.conf.all.drop_gratuitous_arpshows the current value.cat /proc/sys/net/ipv4/conf/all/drop_gratuitous_arpis the raw kernel value.- Inspect the resolved ARP/neighbor table with
ip neigh showto spot poisoning attempts (a known IP suddenly mapped to a new MAC). Usesysctl -a | grep drop_gratuitous_arpto seealland per-interface values.
Remediation
Pavois's harden plan uses the sysctl resource to set net.ipv4.conf.all.drop_gratuitous_arp to 1. It writes the key into a Pavois-managed drop-in and reloads it so unsolicited ARP frames are dropped immediately and after reboot. Apply it with pavois harden apply.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| key | net.ipv4.conf.all.drop_gratuitous_arp |
|---|---|
| resource | sysctl |
| value | 1 |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
The key caveat is IP failover and high availability: keepalived/VRRP, Pacemaker, cloud floating IPs and live-migration all rely on gratuitous ARP to tell the network that a virtual IP has moved to a new MAC. With drop_gratuitous_arp=1, neighbors may not learn the new owner quickly, causing traffic black-holing after a failover. Before applying, exclude hosts that depend on gratuitous-ARP-driven IP takeover, or accept that failover convergence may require an explicit ARP refresh. On a plain single-IP server there is no functional impact and no lockout risk.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| ANSSI BP-028 | R12 | direct | 2.0 | high |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.