dhcpstatus output is right?

jeffrey j donovan donovan at beth.k12.pa.us
Thu Nov 10 15:46:18 UTC 2011


On Nov 10, 2011, at 9:03 AM, GUILLERMO ALVAREZ wrote:

> So, you don’t use dhcpstatus script. You watch directly a copy of the leases file, don`t you?

no sir, im running mac osx, ini files are funny things.

yes Ive written my own set of maintenance scripts top keep tabs. Most of it is live watching, but some is automatic scan logs look for miscreant, ingnore miscreant etc,..

>  
>  
> check for miscreant devices sucking up your ip's. here are my 4 faviorites 
> tail -f /var/log/dhcpd.log | grep pod
> tail -f /var/log/dhcpd.log | grep phone
> tail -f /var/log/dhcpd.log | grep droid
> tail -f /var/log/dhcpd.log | grep blackberry
>  
> give different pools to these devices and you'll find your clients will get their ip's quicker.
>  
> Unfortunately, those are the target devices of that subnet .
> It’s a WiFi network with less security than de official ESSID, just for guests (and casual use) … but that makes it so successful.
> In addition, the security design (captive-portal based) makes easier for devices to get an IP, even if they has not been authenticated yet!
>  
> I think I’ll add more IPs to the pool…

yup sounds about right.

i made 3 pools within the same zone  good bad and ugly using their own device hostname and vender id as the trigger. grouped up very nicely.
each pool I expanded as the good got better and the ugly became ignore/deny.
gl
-j

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/dhcp-users/attachments/20111110/e0f96ceb/attachment.html>


More information about the dhcp-users mailing list