RE: rogue IP address

From: Fields, James (James.Fields_at_bcbsfl.com)
Date: 05/01/03

  • Next message: Benjamin A. Okopnik: "Re: rogue IP address"
    To: "'dondon@pacbell.net'" <dondon@pacbell.net>, security-basics@securityfocus.com
    Date: Thu, 1 May 2003 14:20:43 -0400
    
    

    Sorry if this seems like a dumb question, but you mentioned a "port to IP"
    table in your switch. Does your switch have a "port to MAC address table"?
    Or is that what you actually were referring to?

    If it has that, you can look at the ARP cache in the router for that segment
    and find the MAC associated with the IP address. Then you can compare the
    MAC to the table in the switch to find the port.

    -----Original Message-----
    From: dondon@pacbell.net [mailto:dondon@pacbell.net]
    Sent: Wednesday, April 30, 2003 6:40 PM
    To: security-basics@securityfocus.com
    Subject: rogue IP address

    Someone on our network assigned an IP address to their own system without

    my knowledge. Using LANguard network scanner, the best I can tell is that

    it's a Linux box. The port-to-IP mapping table on our Asante switch

    doesn't see to work correctly.

    Any suggestions on tracing down that system that is associated with the IP

    is appreciated!

    Andy

    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most

    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL
    INCLUSIVE curriculum utilizes lectures, case studies and true hands-on
    utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-security-basics
    ----------------------------------------------------------------------------

    Blue Cross Blue Shield of Florida, Inc., and its subsidiary and affiliate companies are not responsible for errors or omissions in this e-mail message. Any personal comments made in this e-mail do not reflect the views of Blue Cross Blue Shield of Florida, Inc. The information contained in this document may be confidential and intended solely for the use of the individual or entity to whom it is addressed. This document may contain material that is privileged or protected from disclosure under applicable law. If you are not the intended recipient or the individual responsible for delivering to the intended recipient, please (1) be advised that any use, dissemination, forwarding, or copying of this document IS STRICTLY PROHIBITED; and (2) notify sender immediately by telephone and destroy the document. THANK YOU.

    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-security-basics
    ----------------------------------------------------------------------------


  • Next message: Benjamin A. Okopnik: "Re: rogue IP address"

    Relevant Pages

    • RE: Exploit code for IP Smart Spoofing
      ... If there is a MAC violation, this is logged and the port is ... traffic of one other host on the switch. ... but there is no way to protect against ...
      (Bugtraq)
    • RE: snort- problems
      ... #snort is monitoring only the machine that it is installed on. ... port on the switch that it's destination host is attached to. ... Security Engineer ...
      (Focus-IDS)
    • Re: Its War!
      ... they know which port is doing what. ... Once they have that MAC address, ... security seriously, they have tied your MAC address to you. ... log into the router for Internet, the mere fact that you can get ...
      (microsoft.public.windowsxp.general)
    • Re: Down with DHCP!!!!
      ... static IPs. ... your assumption about security is flawed. ... handle mac-based port security. ... or you can set up a RADIUS server with a database of authorized MAC ...
      (Security-Basics)
    • RE: How to find a changing IP on ethernet network
      ... called "port security". ... tell it how many MAC ... to issue an SMTP trap to your Network Management ...
      (Security-Basics)