Red Hat Bugzilla – Bug 58189
RFE: MAC-centric arpwatch instead of IP-centric
Last modified: 2008-05-01 11:38:01 EDT
Arpwatch messages currently report changes in Ethernet address, assuming that a
host's IP address remains stable. In a network where the MAC remains stable and
the IP address changes (eg. DHCP), it would be more useful to receive reports
that use the MAC as the key and report changes in the associated IP address.
This should be a runtime option.
Perhaps this could be useful, but only as an option, and not enabled by default!
However, be prepared for a lot of noise if you have any virtual hosts on your
net, where it's common and perfectly fine to have multiple IP addresses for a
given MAC address. Also, depending on DHCP configuration, you may have a lot of
changes in IP address for a given MAC address, which wouldn't necessarily be
please report such things rfe's upstream...