Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Network "Change Management" |
|---|---|
| Date: | Sun, 19 Sep 2004 01:25:50 +0200 |
Zow Terry Brugger wrote:
Dave,
Does anyone know of a Linux utility that can watch the MAC address
tables in Cisco switches and alert admins as to when a new device has
been plugged in?
I don't work with Cisco switches too much, however you may be able to configure it to send an snmp alert to your Linux box when a new device is plugged in. You'd then use snmp-util (or whatever it's called these days) to handle the message on the Linux side.
I don't think this is possible.
Alternatively you can set up arpwatch on your Linux box and periodically ping your whole range of IPs. Arpwatch will alert you when it sees new or changed MAC addresses for those IPs.
Well, this would only work for IP addresses that are within your subnet, otherwise you'll only get the MAC address of your gateway back.
The easiest thing to do is to poll your router with SNMP, I believe current arpwatch distributions can do that too, so you would have both at once.
This can be set up so users will actually have to log in for layer 2 access, and when they're authenticated, you could for example get a RADIUS accounting message that will give you, among other things, the user's MAC address and his login name.
Regards, Fred Leeflang
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Network "Change Management", Jorge Reyes |
|---|---|
| Next by Date: | RE: Network "Change Management", Bill Nash |
| Previous by Thread: | Re: Network "Change Management", Zow |
| Next by Thread: | RE: Network "Change Management", Jorge Reyes |
| Indexes: | [Date] [Thread] [Top] [All Lists] |