APLawrence.com -  Resources for Unix and Linux Systems, Bloggers and the self-employed

'arpwatch' for security and administration

Our network is comprised of mostly static IP addresses, but I do run a DHCP server, for about 8 or so IP addresses. I use static IP's mostly for security, and auditing reasons. It is much harder to audit someones actions on their PC, if their IP address keeps changing. Sure, you can mess around with the MAC address, but most TCP/IP apps work with IP addresses. Since I do allow DHCP, I run 'arpwatch' as a daemon, keeping me informed when a new machine gets an address from the network. It emails me the IP address that it is currently leasing, as well as the MAC address. This information helps me keep track of who and when. It will also inform me if the MAC address for a static IP changes. This way I can ask around and see if someone is doing something they shouldn't be. It would also alert me if someone was messing with their network setting, and changing their IP address to one of a gateway, or server.

'arpwatch' is also a useful administration tool. We recently purchased 7 HP print servers for some printers, and new offices. Since they initially get their IP address from a DHCP server, arpwatch emails me when I put a print server on the network. I can then telnet to the print sever, set up a static IP address, and save the settings. This is a lot easier than using the HP cdrom, and Windows software to manually configure each one with a static IP address.

Check out the manpage of arpwatch for other useful features.

Copyright August 2003 Bruce Garlock All rights reserved


Got something to add? Send me email.





(OLDER)    <- More Stuff -> (NEWER)    (NEWEST)   

Printer Friendly Version

-> -> 'arpwatch' for security and administration




Increase ad revenue 50-250% with Ezoic


More Articles by © Bruce Garlock



Kerio Connect Mailserver

Kerio Samepage

Kerio Control Firewall

Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more.

Contact us





Perl: The only language that looks the same before and after RSA encryption. (Keith Bostic)

There are only two things wrong with C++: The initial concept and the implementation. (Bertrand Meyer)







This post tagged: