We have a small network of around 100 laptop/desktops and around 20 servers (sounds an overkill but these servers provide service for all our external contractors too) and we have recently noticed that our Exchange CAS server has been hacked. The hackers installed VPN server and were using our network to go out again. We have also noticed that they installed number of Malwares. We have so far cleaned that machine however we have now got another problem with ARP attack.
There is a nonstop sequential arp request to all the ip's in the subnet and almost every minute our Juniper firewall (gateway) MAC is being swapped for our Juniper VPN device which as a result is making Internet access unavailable to staff members since the Barracuda box is the wrong box to be routing traffic.
Finally there is a nonstop request/reply of ARP to 0.0.0.0 and a none existing MAC address in my network.
We use Cisco 2800 router for the internet and all our internal switches are HP Procurve while we have a mix of Windows and Linux servers running in the network. Also, all our servers are Vmware Vsphere virtualised.
I'm so far reaching my limit in identifying the machine(s) causing this problem and any help ideas would be highly appreciated.
----Edit---
I have since run Wireshark on the network as you guys suggested and there is a weird pattern that I have noticed. My Juniper VPN device's MAC address is being allocated to my Juniper firewall which as a result is cutting off Internet connection and also Wireshark says my Barracuda box IS the source as can be seen from the this image below: https://i.stack.imgur.com/i7T0p.png