Arpwatch
Platforms:
AIX,
BSDI,
DG-UX,
FreeBSD,
HP-UX,
IRIX,
Linux,
NetBSD,
OpenBSD,
SCO,
Solaris,
SunOS,
True64 UNIX,
Ultrix,
UNIX
Categories:
Intrusion Detection,
Network,
Network,
Sniffers,
Utilities
Version:
URL:
Arpwatch is a tool that monitors ethernet activity and keeps a database of ethernet/ip address pairings. It also reports certain changes via email. Arpwatch uses libpcap, a system-independent interface for user-level packet capture. Before building tcpdump, you must first retrieve and build libpcap, also from LBL, in: ftp://ftp.ee.lbl.gov/libpcap-*.tar.Z.

A series of enhancements has been prepared for FreeBSD that allows arpwatch to monitor ethernet device activity over multiple interfaces, among other things. It is based on arpwatch 2.1a11 and can be found at http://www.secureworks.com/open
[ reply ]