Skip to main content
Version: current

alert


ip/dhcp-server/alert​

Type: Directory

Detects unknown (rogue) DHCP servers on an interface. The alert sends its own DHCPDISCOVER about once a minute, and checks the source of every DHCP reply it sees against valid-server. An unknown server is logged with the dhcp,critical topics, listed in unknown-server, and triggers on-alert. Because the alert sends DHCP requests itself, do not use it on an interface where the router runs a DHCP client. For details, see DHCP Server.

FlagNameDescription
XdisabledThe alert is disabled. New alerts are created disabled.
IinvalidThe alert configuration is invalid.
ArgumentTypeDescription
interface ( mandatory )iface_enumInterface to watch for DHCP servers.
valid-servermulti { mac-address: macAddr }MAC addresses of the DHCP servers that are allowed on the interface. Replies from other servers raise an alert.
on-alertalt { script: string }Script to run when an unknown DHCP server is detected.
alert-timeoutalt { symbolic-names: enum (none) { none:0 } , time-interval: time }Time after which a detected server is forgotten. If the server is still present afterwards, a new alert is raised. With none, detected servers are never forgotten. Default: 1h.
Read-only ArgumentTypeDescription
unknown-servermulti { mac-address: macAddr }MAC addresses of the unknown DHCP servers that were detected.