ip/dhcp-server/alert
Type: Directory
Detects unknown (rogue) DHCP servers on an interface. The alert sends its own DHCPDISCOVER about once a minute, and checks the source of every DHCP reply it sees against valid-server. An unknown server is logged with the dhcp,critical topics, listed in unknown-server, and triggers on-alert. Because the alert sends DHCP requests itself, do not use it on an interface where the router runs a DHCP client. For details, see DHCP Server.
| Flag | Name | Description |
|---|
| X | disabled | The alert is disabled. New alerts are created disabled. |
| I | invalid | The alert configuration is invalid. |
| Argument | Type | Description |
|---|
| interface ( mandatory ) | iface_enum | Interface to watch for DHCP servers. |
| valid-server | multi { mac-address: macAddr
} | MAC addresses of the DHCP servers that are allowed on the interface. Replies from other servers raise an alert. |
| on-alert | alt { script: string
} | Script to run when an unknown DHCP server is detected. |
| alert-timeout | alt { symbolic-names: enum (none) { none:0 }
, time-interval: time
} | Time after which a detected server is forgotten. If the server is still present afterwards, a new alert is raised. With none, detected servers are never forgotten. Default: 1h. |
| Read-only Argument | Type | Description |
|---|
| unknown-server | multi { mac-address: macAddr
} | MAC addresses of the unknown DHCP servers that were detected. |