Hi. I am trying to conduct an ARP spoofing attack on my system. I have 2 systems set up in VMware. I am using kali linux. When I start sniffing the packets using arpspoof tool, the internet connection in the victim system stops. Why is this happening?

Jul 25, 2019 in Cyber Security & Ethical Hacking by Vasu

This happens if you have not enabled packet forwarding. When you are running arpspoof, the packets between the victim and the broadcast flows through Kali and you have to set kali to allow to forward these packets. You can solve this by enabling packet forwarding. To do this, run the below command in the terminal:

echo 0 > /proc/sys/net/ipv4/ip_forward

answered Jul 25, 2019 by Anis
I have tried this doesn't work

please can anyone give a reason?
Can you mention the steps that you followed?
it has to be " echo 1 > /proc/sys/net/ipv4/ip_forward"
I have also tried these steps but still killing the internet connection of victim.

Can anyone help me to solve this issue

Hey, @Subhadip,


ARP spoofing usually works by fooling all the clients into thinking that you're the router, by faking the ARP responses that translate IP addresses to MAC addresses. When clients receive the ARP response, they remember the MAC that was associated with the IP.

Once you stop the application that's handling the man-in-the-middle part of the operation, the clients keep sending to your MAC address, instead of the routers. Since you're no longer handling such packets, the traffic is blackholed and the whole network goes down. Resetting the router causes it to send an ARP broadcast (e.g. "Hi, I'm at 12:34:56:78:90:AB") along with a DHCP broadcast, allowing clients to re-sync with the real router.

It may be possible for your ARP poisoning software to send out an ARP broadcast when it closes, with the real MAC address of the router, in order to prevent this. This may be a bug, or it may just not be implemented yet.

Thanks for your reply

could you please tell me what are the steps are to be followed to execute arp spoof along with wireshark to capture the network traffic along with http credentials that victim uses.

I am using kali linux on VMware as virtual machine and the host machine is having Mac Os.

Actually i have tried to sniff to my own mobile phone.

Hey, @Subhadip,

Regarding the steps required, I would suggest you check this blog out where all the necessary steps have been mentioned

Hope this helps!!

