Re: arpwatch and snort help

From: prg (rdgentry1_at_cablelynx.com)
Date: 12/20/04


Date: 20 Dec 2004 13:46:38 -0800

Jason Benway wrote:
> I setup my first linux box last week.

Just in time for the holidays ;-)

> Its running Fedora core 3.
>
> When I set it up I only had 1 NIC. it is on our main subnet.
>
> I installed a second NIC and I was able to get it working. I've setup
the
> second nic on a mirroreds switch port so it can see traffice on 4 of
our
> VLANS (each VLAN is on a different subnet)
>
> I would like to setup arpwatch to only use the second NIC and for it
to
> alert me to traffic on all VLANs.
> I've seen the -n switch for arpwatch, but how do I use that when
arpwatch is
> running as a service?
>
> How do I use the -n switch when the subnets are not together
(example:
> 10.0.0.1,192.168.1.1,192.168.42.1)
>
> I would also like to setup snort to only listen on the second NIC
>
> Thank you
> jb

Much will depend on the switch and its OS as to whether you can monitor
multiple vlans simultaneously. What kind of switch and OS are using?

Do you think that arpwatch -n will _allow_ you to monitor multiple
subnet IPs of different classes/widths? That is not my understanding
-- I've never needed to use the switch. I always assumed it was to
_restrict_ and _assure_ that arpwatch was monitoring only one subnet --
ie., don't distract me with bogons and martians -- or was monitoring
subnets of equal width (prefix length) in a (more or less) contiguous
range of address space. But I could easily be wrong ;-)

As far as snort and vlan monitoring are concerned, again I think it
will largely depend on your switch and network topology. Set up
monitoring at point(s) of traffic concentration.

This is all pretty much off the top of my head from playing with vlans
prior to a failed roll-out a few years back -- ie., a prototype "lab"
setup.

Also you may want/need to get on a mailing list more specific to your
hardware and software tools. http://www.tcpdump.org/lists/ might be
one to start with -- suspect folks there familiar with arpwatch as
well. Also:

http://www.mcabee.org/lists/snort-users/
http://www.ethereal.com/lists/

http://www.cisco.com/warp/public/473/41.html
basic setup for Cisco SPAN (swited port analyzer)
hth,
prg
email above disabled



Relevant Pages

  • VLANS in a DMZ - good idea?
    ... I am looking to setup a new perimeter network for a client and am ... VLANS setup on the switch and equally Firewall 2 will only allow ...
    (comp.security.firewalls)
  • Re: PIX and VLANs
    ... When VLANs are used on a switch you have to setup a router. ...
    (comp.security.firewalls)
  • Re: polling(4) rocks!
    ... > across a dozen of vlans. ... There is nothing special about its setup ... it was able to switch full 10Mbytes/sec of traffic ... > With polling on, interrupt time never exceeds 5% and it stays as low ...
    (freebsd-net)
  • bonding, link aggregation, and switch config
    ... I'm trying to setup bonding with 2.4.20 kernel and have a few questions. ... Link aggregration does not work. ... Link aggregration with ARP interval: I ran #1 again using ARP ... How does the switch handle the same MAC on both ports? ...
    (comp.os.linux.networking)
  • Re: Accidently removed monitoring tool and cannot reinstall
    ... What happens if you just try to install Monitoring ... > server setup and keep coming up with this error. ... > "An error occurred while creating distribution groups. ... >>>Merv Porter ...
    (microsoft.public.windows.server.sbs)