OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • New Device Alert
« previous next »
  • Print
Pages: [1]

Author Topic: New Device Alert  (Read 9154 times)

nmiller0113

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
New Device Alert
« on: July 15, 2017, 10:26:58 am »
I recently moved from Untangle to opnsense.  Everything is running great but I cannot seem to figure out a good way to get alerts when new devices appear on my internal network(s).  I like to be aware of new connections so I know if someone new jumped on my wireless or connected to my LAN.  It's just for the sake of knowing and making sure it's legit and not some rogue device.  Untangle had an easy way of doing this, and I understand that opnsense is a completely different platform and I'm not necessarily looking for an as easy solution...just *a* solution...either using what's part of the platform by default or through the use of an additional features.  Either works for me, I just want to be able to get an email every time a device, not previously known or on the network, connects.  Thanks!
Logged

MasterXBKC

  • Jr. Member
  • **
  • Posts: 66
  • Karma: 6
  • Infragard Member
    • View Profile
    • PFMonitor Central Firewall Management
Re: New Device Alert
« Reply #1 on: July 16, 2017, 02:47:43 am »
I could make this work for you, i have built a number of tool for pfsense and opnsense. 
Logged
Member of FBIs Infragard Program
Certified Information Systems Security Officer
Certified Vulnerability Assessor
PFMonitor Remote Management, Backup, & Live Monitoring for PFSense and OPNSense
OPNSense Units: R720XD XL, R720XD XL, R720XD, R720XD, R710, DL360G7, QNAP

nmiller0113

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
Re: New Device Alert
« Reply #2 on: July 17, 2017, 08:14:43 pm »
Awesome!  How hard would it be to create?
Logged

Micky

  • Jr. Member
  • **
  • Posts: 99
  • Karma: 11
    • View Profile
New Device Alert
« Reply #3 on: July 17, 2017, 08:39:39 pm »
You could use a raspberry with nmap-skript, too. If unknown Clients were found you can send a pushover-message or mail ...

Gr. Micky
« Last Edit: July 17, 2017, 08:41:53 pm by Micky »
Logged

beren

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
Re: New Device Alert
« Reply #4 on: October 08, 2019, 05:43:04 pm »
I know this is old, but has anyone come up with an easy solution? It would be really nice if it could use the dhcp static lease file as filter as well, so known devices don't get logged.
Logged

Mark1

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: New Device Alert
« Reply #5 on: October 17, 2019, 05:09:35 pm »
Hi,

is it to trivial or is there simply no solution to receive an email on new devices?

I would really appreciate a short feedback whether it is possible or not.

Thanks,

Mark
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: New Device Alert
« Reply #6 on: October 17, 2019, 06:02:19 pm »
I don't know an easy way to make the DHCP server send an email for every new (!) lease. Would be interesting for other functions (IDS), too...

If you want to hand down IPs on your network manually (reserved for MAC) this can be done quite easily.
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: New Device Alert
« Reply #7 on: October 17, 2019, 08:19:40 pm »
You can try to install arpwatch via ports
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Mark1

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: New Device Alert
« Reply #8 on: October 22, 2019, 12:13:32 pm »
Thank you.
Conclusion, with the standard opnsense release a new device alert is not possible.

Interesting fact as the first question from the GDPR guy was how we get notified on new devices.



Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: New Device Alert
« Reply #9 on: October 22, 2019, 12:18:06 pm »
What about new devices not using your gateway?

I would try switch port security and block unknown devices on access layer --> 802.1x.
New devices have to request a computer certificate in IT dept.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: New Device Alert
« Reply #10 on: October 22, 2019, 01:11:40 pm »
Quote from: hbc on October 22, 2019, 12:18:06 pm
What about new devices not using your gateway?

I would try switch port security and block unknown devices on access layer --> 802.1x.
New devices have to request a computer certificate in IT dept.

Indeed a way better solution
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: New Device Alert
« Reply #11 on: January 03, 2022, 03:45:06 pm »
There is now one :)

https://forum.opnsense.org/index.php?topic=20827.msg126436#msg126436
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • New Device Alert
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2