Client Gateway Attacker Switch

ARP Spoofing vs. Dynamic ARP Inspection — 2D Swimlane View

ARP has no built-in authentication, which is exactly what makes cache poisoning possible: a rogue host on the LAN broadcasts a forged reply claiming to own the gateway's IP address, and the switch faithfully forwards traffic to whatever MAC the client's cache currently believes. This 2D simulator renders the same discrete-event model as a scrolling sequence diagram — four swimlanes, arrows for every ARP reply and data packet, and a scrolling cache-state trace — and lets you launch the attack at a rate you control while a live counter of intercepted and blocked packets makes the effect measurable. Flip on Dynamic ARP Inspection and watch forged arrows stop dead at the Switch lane instead of ever reaching the Client.