Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is something wrong with arpwatch?

    Scheduled Pinned Locked Moved pfSense Packages
    3 Posts 2 Posters 615 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      scilek
      last edited by

      I use arpwatch to track and log ARP activity on one router (v 2.6.0-RELEASE):

      70324a29-0ccc-40b5-9e17-add767236f42-image.png

      Of course, the service is configured and enabled:
      9deff2d3-9fb0-4d0c-8fbe-00f12413000c-image.png

      Ad it is evident from the command line:

      [2.6.0-RELEASE][root@router.somesite.com]/root: ps -aux | grep arpwatch
      root   84346   0.0  0.3   47416  37824  -  Ss   10:06      0:00.07 /usr/local/sbin/arpwatch -v -N -z -C -f /usr/local/arpwatch/arp_bge3.dat -i bge3
      root   84654   0.0  0.3   47428  37848  -  Ss   10:06      0:00.10 /usr/local/sbin/arpwatch -v -N -z -C -f /usr/local/arpwatch/arp_bge3.4.dat -i bge3.4
      root   85278   0.0  0.3   47320  37800  -  Ss   10:06      0:00.05 /usr/local/sbin/arpwatch -v -N -z -C -f /usr/local/arpwatch/arp_bge3.3.dat -i bge3.3
      root   85752   0.0  0.3   47320  37808  -  Ss   10:06      0:00.06 /usr/local/sbin/arpwatch -v -N -z -C -f /usr/local/arpwatch/arp_bge3.5.dat -i bge3.5
      root   56457   0.0  0.0   11268   2504  0  S+   10:24      0:00.00 grep arpwatch
      

      Reporting of bogons is disabled, and that is what the -N flag does.

      However, I have tonnes of useless messages in the general log.
      93a2ebb1-f0e6-4289-a8cc-58523e80e5db-image.png

      I have deleted thousands but they keep coming, smothering useful information.

      Is this a bug in arpwatch 3.1 ?

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @scilek
        last edited by NogBadTheBad

        @scilek Does this occur with anything apart from your Hikvision devices, if not I'd disable arpwatch on LAN_CAM or suppress the MAC addresses?

        AC:B9:2F Hangzhou Hikvision Digital Technology Co.,Ltd.

        BC:9B:5E Hangzhou Hikvision Digital Technology Co.,Ltd.

        https://www.wireshark.org/tools/oui-lookup.html

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        S 1 Reply Last reply Reply Quote 1
        • S
          scilek @NogBadTheBad
          last edited by

          @NogBadTheBad

          I just did that and it stopped, and i think I know why. Those cams use L2 for discovery.

          Thank you very much!

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.