|
NAMEndpmon - Neighbor Discovery Protocol MonitorSYNOPSISndpmon [ -i interfacename ] [ -f configfile ] [ -d dtd_file ] [ -F filter ][ -n number ] [ -L ] [ -v ] [ -h ] [ -d dtd_file ] [ -g neighbor_file ] DESCRIPTIONNDPMon is a monitoring software for ipv6 Neighbor Discovery. It syslogs activity and reports by email malicious ND message. NDPMon uses libpcap to listen for icmp6 packets and libxml2 to use configuration and neighbor cache files.The -i flag is used to change the default interface eth0. The -f flag is used to change the path of the configuration file. The default is /usr/local/etc/config_ndpmon.xml The -e flag is used to change the path to the DTD file for the configuration file. The default is /usr/local/share/ndpmon/config_ndpmon.dtd The -n flag uses libpcap to specify a limited number of packet to capture. The -F flag allows to change the default icmp6 filter. The -L flag is used to disable syslog and mail reports. This is used to do a learning phase and constitue the neighbor cache. The -v is used to enable the DEBUG mode. The -d flag is used to change the path to the DTD file for the neighbor cache. The default is /usr/local/share/ndpmon/neighbor_list.dtd The -g flag is used to change the path to the neighbor cache. The default is /usr/local/var/ndpmon/ndpmon_neighbor_list.xml Note that an empty neighbor_cache.xml file must be created before the first time you run ndpmon. NDPMon must be run with root rights to work. REPORT MESSAGESHere's the list of the report messages generated by ndpmon:
SYSLOG MESSAGESHere are some of the syslog messages; note that messages that are reported are also sysloged.
FILESconfig_ndpmon.xml - contains settings which must be fill by the administrator neighbor_list.xml - neighbor cache: all neighbors known to be on the link SEE ALSOarpwatch(8) ipv6(7), pcap(3), libxml(3).AUTHORThibault Cholez and Frederic Beck for MADYNES Project, Loria, Fr.BUGS
Visit the GSP FreeBSD Man Page Interface. |