Arpwatch is a tool to monitor the ARP activity of your local network. Its main goal is to detect poisoning attacks. It'll first create a database of IP<->mac associations (the database is /var/lib/arpwatch/arp.dat). Then, it'll be able to detect changes, and send an email to the admin.
- SME Server 7.X,8.X,9.X 10.x
- install the rpms
yum --enablerepo=smecontribs install smeserver-arpwatch
- Start the daemon
Log into your server using SSH, and start the daemon (this should not be necessary for SME10)
expand-template /etc/sysconfig/arpwatch /etc/init.d/arpwatch start
signal-event post-upgrade && signal-event reboot
Change recipient from admin to your user
If you'll like to send notifications to other user / group copy the ALL file located in /etc/e-smith/templates/etc/sysconfig/arpwatch to newly created folder /etc/e-smith/templates-custom/etc/sysconfig/arpwatch
mkdir -p /etc/e-smith/templates-custom/etc/sysconfig/arpwatch cp /etc/e-smith/templates/etc/sysconfig/arpwatch/ALL /etc/e-smith/templates-custom/etc/sysconfig/arpwatch/
edit the file ALL and change the user domain...
expand-template /etc/sysconfig/arpwatch /etc/init.d/arpwatch restart
You may have some emails the first days you run it, because it'll see new computers on the network. Just let it running a few days. Then, you should only receive alerts when a new machines connects or when something wrong appens (arp spoofing attack)
You may also have problems if you runs arpwatch with OpenVPN Bridge contrib. The reason is that your client will have a dynamic IP. This problem can be solved if you fixe an IP for each client using the configuration rules manager. The second problem is that OpenVPN client will generate a random mac adress for each connection. So once again, you may have a lot of false positives. You can also solve this issue if you fixe a mac address in the client configuration:
Of course, choose a unique mac address for each client.
If you want to remove the contrib, just run:
/etc/init.d/arpwatch stop yum remove arpwatch
The source for this contrib can be found in the smeserver CVS on sourceforge.
|ID||Product||Version||Status||Summary (4 tasks)|
|SME Contribs||10alpha||RESOLVED||Initial Import to SME 10 tree [smeserver-arpwatch]|
|8127||SME Contribs||8.0||UNCONFIRMED||not enough data about mac address database|
|8126||SME Contribs||8.0||UNCONFIRMED||If you have the contrib OpenVPN will not assign the correect interface|
|7802||SME Contribs||8.0||UNCONFIRMED||feature request - send info about unused mac / IP for certain period of time|