Please login to access that KB Article

Packet Spoofing Detected Events Triggered by WLAN Anti-Spoofing ARP/DHCP Rate Limits

Summary

In high-density WLAN deployments, restrictive Anti-Spoofing ARP and DHCP request rate limits can generate packet spoofing alarms. Although clients continue to authenticate and receive valid IP addresses, SmartZone may report spoofing-related events when legitimate roaming and DHCP renewal traffic exceeds configured thresholds.

Question

Why does SZ generate repeated "Packet Spoofing Detected", "L2 Source MAC Spoofed", "ARP Request Rate Limit Exceeded", and "DAI (ARP Spoofing) Detected" events across multiple APs even though clients successfull

Customer Environment

SmartZone Anti-Spoofing enabled on the WLAN ARP Request Rate Limit configured DHCP Request Rate Limit configured

Symptoms

  • Repeated "Packet Spoofing Detected" events reported by the controller.
  • "L2 Source MAC Spoofed" alarms observed across multiple APs.
  • "ARP Request Rate Limit Exceeded" events reported.
  • "DAI (ARP Spoofing) Detected" messages generated.
  • Events observed across multiple clients rather than a single endpoint.
  • Clients continue to authenticate successfully and obtain valid DHCP leases.
  • No AP hardware, resource, or stability issues observed.
  • Issue predominantly affects WLANs with high client density and roaming activity.

Root Cause

The WLAN Anti-Spoofing policy was configured with restrictive ARP and DHCP request rate-limit values. In a WLAN environment with a high number of roaming clients, frequent client associations, reassociations, DHCP renewals, and ARP exchanges generated traffic that exceeded the configured thresholds. As a result, legitimate client traffic could be classified by the Anti-Spoofing engine as spoofed traffic, leading to false-positive spoofing detections and packet-drop events.

Troubleshooting Steps

  • Review SmartZone event logs and identify recurring spoofing-related alarms.
  • Collect SmartZone snapshot logs and AP support logs during the occurrence of the events.
  • Verify whether affected clients are successfully authenticating and receiving valid DHCP leases.
  • Review client roaming and reassociation activity associated with the reported events.
  • Verify WLAN Anti-Spoofing configuration settings, including ARP and DHCP request rate limits.
  • Determine the number of active clients on the affected WLAN and evaluate client mobility patterns.
  • Review WLAN and AP security settings to confirm whether Rogue AP protection is enabled.
  • Compare behavior across other WLANs to determine whether the issue is isolated to a high-density guest SSID.
  • Correlate event timestamps with client roaming, DHCP renewals, and ARP activity.

Resolution

  • Identify that the affected WLAN has Anti-Spoofing enabled with restrictive rate-limit values.
  • Confirm that the WLAN services a large population of roaming and transient clients.
  • Disable the WLAN Anti-Spoofing feature.
  • Allow the updated WLAN configuration to propagate to all access points.
  • Monitor the environment for recurrence of spoofing-related events.
  • Verify that no additional "Packet Spoofing Detected" events are reported after the configuration change.

Article Number:
000015485

Updated:
August 03, 2026 03:17 AM (about 1 month ago)

Tags:
Troubleshooting, Configuration, SmartCell Gateway

Votes:
0

This article is:
helpful
not helpful

Working...Please wait

This is here to prevent you from accidentally submitting twice.

The page will automatically refresh.

Alert!!

Close