Hi, > Unfortunately, I'm having a terrible time finding the rule for it. I > can keep looking, but if you know the default location, I'd appreciate > the nudge in the right direction. I've tried searching all the files in > /usr/local/pf/conf/snort There is no rule for it... It looks at the DHCP request PF receives, and check if the DHCP server ip match one in general.dhcpservers. If it doesn't then it fires the violation.
Thanks. -- Francois Gaudreault, ing. jr [email protected] :: +1.514.447.4918 (x130) :: www.inverse.ca Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence (www.packetfence.org) ------------------------------------------------------------------------------ Don't let slow site performance ruin your business. Deploy New Relic APM Deploy New Relic app performance management and know exactly what is happening inside your Ruby, Python, PHP, Java, and .NET app Try New Relic at no cost today and get our sweet Data Nerd shirt too! http://p.sf.net/sfu/newrelic-dev2dev _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
