I’m seeing a lot of recurring ARP traffic for dead hosts and the source is a cisco router that connects to our WAN locations. THe traffic isnt killing the network but its annoying (approx 75 arps over 300 seconds). By dead hosts, i mean valid addresses which arent currently active.
My goal is to find what device[s] (either on this side of the wan or the remote side) are trying to contact those dead hosts via the cisco router.
I’ve enabled arp debugging to a syslog but that is just showing me the same local arp broadcasts im seeing in wireshark.
how can i learn the src host that is “asking” this router for these dead hosts?