My VPS provider just suspended my VPS, and they showed me this below error in the server log, claiming that this is the reason for suspension.

I don't understand what this error is. Can someone explain?

OS is centos6 OS I think.

Apr 10 14:52:46 box4 arpwatch: flip flop fa:ed:21:37:78:97 (00:24:dc:7b:5f:c0) ens18

Apr 10 14:52:46 box4 arpwatch: flip flop 00:24:dc:7b:5f:c0 (fa:ed:21:37:78:97) ens18

Apr 10 14:52:48 box4 arpwatch: flip flop 00:24:dc:7b:5f:c0 (fa:ed:21:37:78:97) ens18

Apr 10 14:52:50 box4 arpwatch: flip flop 00:24:dc:7b:5f:c0 (fa:ed:21:37:78:97) ens18

Apr 10 14:52:52 box4 arpwatch: flip flop 00:24:dc:7b:5f:c0 (fa:ed:21:37:78:97) ens18
  • 1
    Is it from your VM or their host?
    – Tom Yan
    Commented Apr 11, 2021 at 8:03
  • 1
    I don't know. They sent me just this and one line saying that my VPS is suspended. I paid them 2 days ago...
    – John
    Commented Apr 11, 2021 at 8:53
  • @John Did you try to spoof MAC Address or poison the ARP cache by anyway? Commented Apr 11, 2021 at 9:13
  • Honestly, I don't even know what it means, poison ARP cache. I don't even know what arp is.
    – John
    Commented Apr 11, 2021 at 10:33
  • Is it possible that my root passsword is compromised
    – John
    Commented Apr 11, 2021 at 10:34

1 Answer 1


From the arpwatch manual (the service that generated the error you posted):

Flip Flop: The ethernet address has changed from the most recently seen address to the second most recently seen address.

It would seem that the hosting provider does not allow network interfaces to change their MAC address, and this log is saying that it was.

ARP -- address resolution protocol -- is the networking protocol that allows machines to find the current hardware address (MAC address) connected with an IP address. These connections, once requested, are stored in an ARP Table in routers/switches/etc.

ARP Poisoning, is when a machine replies to the "who has IP address x.x.x.x" query on the network, either completely fraudulently, or by nature of having two machines on the network with network interfaces with identical MAC addresses. The table is said to be poisoned because traffic will now be routed to the malicious/miss-configured machine.

Hope that helps.

  • So if I did not do it, then would it mean that the server is hacked? What should I do now to get the server back up running? Hosting provider has suspended it.
    – John
    Commented Apr 12, 2021 at 1:01
  • As for the possible security implications of such an error, or the root cause, that is out of my expertise. Perhaps a new question on Server Fault stack exchange site? serverfault.com
    – superboot
    Commented Apr 12, 2021 at 20:54

You must log in to answer this question.

Not the answer you're looking for? Browse other questions tagged .