Re: Network "Change Management"

From: Sam Baskinger (sam_at_reefedge.com)
Date: 09/16/04

  • Next message: Evan Pierce: "RE: Network "Change Management""
    Date: Thu, 16 Sep 2004 14:05:07 -0400
    To: Dave Torre <dtorre@fostercity.org>
    
    

    Hi Dave and Folks,

    The "canonical" solution is to put an IDS on a monitoring port on the
    Cisco. That device will see all traffic on the switch and you can run
    something like arpd. The nice thing about this is that there is no
    polling involved. When a new PDU appears the arpd can take action
    immdiately.

    Hope this helps.

    Sam

    Dave Torre wrote:

    >Does anyone know of a Linux utility that can watch the MAC address
    >tables in Cisco switches and alert admins as to when a new device has
    >been plugged in?
    >
    >Basically, we have your standard client network with DHCP. Internet
    >access is restricted to authenticated users, and so are the file shares.
    >However, we've had a few instances where people just plug in their
    >personal laptops which makes me very worried...
    >
    >Any thoughts/suggestions as to how I can monitor such events in real
    >time?
    >
    >Thanks,
    >-Dave
    >
    >


  • Next message: Evan Pierce: "RE: Network "Change Management""

    Relevant Pages

    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Re: VPN over wireless
      ... I personally use Cisco since I am Cisco Certified. ... Support with a Cisco Switch it would work. ... on my network - and no success. ... You will still the need the Router to issue DHCP and ...
      (microsoft.public.windows.server.sbs)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Re: Brocade / Cisco interop issue
      ... By bouncing the host port connected to the Cisco switch you're causing the ... to see if this removes the Brocade failure. ...
      (comp.arch.storage)
    • Re: Cisco vs. Netgear: 24 port gigabit managed switch
      ... The Baystack 450 is 10/100 with no gigabit. ... All three of my 450 stacks connect up to our HP9304 backbone switch via gig ethernet on multimode. ... But the Cisco 2970 and 3560 and 3750 are noticably more flexible ... layer 3 facilities for about 6 months, ...
      (comp.dcom.lans.ethernet)