Hi,

> Unfortunately, I'm having a terrible time finding the rule for it.  I
> can keep looking, but if you know the default location, I'd appreciate
> the nudge in the right direction.  I've tried searching all the files in
> /usr/local/pf/conf/snort
There is no rule for it... It looks at the DHCP request PF receives, and 
check if the DHCP server ip match one in general.dhcpservers. If it 
doesn't then it fires the violation.

Thanks.


-- 
Francois Gaudreault, ing. jr
[email protected]  ::  +1.514.447.4918 (x130) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence 
(www.packetfence.org)

------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to