MAC Address Monitoring

Associate
Joined
5 Oct 2004
Posts
1,647
Is there any software out there that will keep a database of all the MAC addresses currently on my network and then send me an email alert if one pops up that has not been seen before?
 
Sounds like you want to identify rogue machines on your network? or lock it down?

I manage this from another angle, IP addresses are only given to machines whose mac addresses are in an approved list. We use InfoBlox for this, which isn't cheap. But it can be achieved with standard DHCP by assigning a specific IP address to a mac address.

Don't know if that helps
 
I need to see if someone plugs in an unrecognised machine, I don't really want to spend loads of money on a tool to do as it is pretty unlikely to happen in our small office but it is something we need to be aware of

We don't use Sophos AV so no NAC

Does 2008 server have NAC built in?
 
theres a mac trackmodule in Cacti that we use. it periodically queries the network switches via snmp and keep a database of what port they are on etc and also you can do alerting for specific Macs

if needed i reakon we could get it to trigger an action to connect to the relevent switch port and shut it down if needed.

we mainly use it to track down rouge dhcp servers that average 1 per year.
 
If I was to buy a single switch capable of doing 802.1x and plug my DHCP server into that would I be able to only assign IP address' to the devices I permit?
 
As I said earlier, you could do this purely from DHCP by assigning static IP addresses to your machines and setup exclusions. If you have a small number of machines this is quiet manageable - I have 600ish I manage this way. But it depends how secure you want to be, for me this is enough, our students are barely computer literate :)

An attacker would have to steal an IP address from a machine and set it statically or spoof a MAC to get access to the network.

You could also setup something like Cacti monitoring MAC addresses as an extra precaution
 
Back
Top Bottom