Re: [Kea-users] Kea DHCP forensic logging (Darren Ankney)

2025-02-13 Thread Darren Ankney
e so it is more specific than "Re: > Contents of Kea-users digest..." > > > Today's Topics: > >1. Re: Kea DHCP forensic logging (Darren Ankney) >2. Re: > https://urldefense.proofpoint.com/v2/url?u=http-3A__keama-2Dleases.py&d=DwICAg&c=euGZstcaTDllvimEN8b7jXrwq

Re: [Kea-users] Kea DHCP forensic logging (Darren Ankney)

2025-02-12 Thread Jim Springsteen
0XVyNPjSoh9GnI-jjmPD-Tsx_U6eggOZX4FIuEiCYnEfH-3rRfS_h0tNidlbkUU&s=FauJqGAUuamJTUkl5hcagnHdqjLXW8Wig1f_Ux-FO4k&e= fails with abandoned leases (Darren Ankney) -- Message: 1 Date: Thu, 6 Feb 2025 08:31:30 -0500 From: Darr

Re: [Kea-users] Kea DHCP forensic logging

2025-02-06 Thread Jason Creviston
s uses regularly updated anti-virus software in an attempt to reduce the possibility of transmitting computer viruses. We do not guarantee, however, that any attachments to this Email are virus-free. ________ From: Kea-users on behalf of Darren Ankney Sent: Thursda

Re: [Kea-users] Kea DHCP forensic logging

2025-02-06 Thread Darren Ankney
://urldefense.proofpoint.com/v2/url?u=http-3A__darren.ankney-40gmail.com&d=DwICAg&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=eCjTemB5sg6isrvXubUeohlcjyd3d-BSpS2k69PYabI&m=id4thKZ4cnPfMJjYEfye3UIJQlg2-EHjb-jEReUtM2hj8URdoQJynRlNRK59RmKx&s=r9HpK1I_3VjlqAgvYFxPJLuNYE1_JphqEqeRcnpD

Re: [Kea-users] Kea DHCP forensic logging

2025-01-29 Thread Jim Springsteen
qOf-v5A_CdpgnVfiiMM&r=eCjTemB5sg6isrvXubUeohlcjyd3d-BSpS2k69PYabI&m=id4thKZ4cnPfMJjYEfye3UIJQlg2-EHjb-jEReUtM2hj8URdoQJynRlNRK59RmKx&s=r9HpK1I_3VjlqAgvYFxPJLuNYE1_JphqEqeRcnpDFfg&e=> To: "Kea user's list" Subject: Re: [Kea-users] Kea DHCP forensic logging Message-I

Re: [Kea-users] Kea DHCP forensic logging

2025-01-28 Thread Darren Ankney
onald Blaas) > > > -- > > Message: 1 > Date: Thu, 23 Jan 2025 13:27:59 -0500 > From: Darren Ankney > <https://urldefense.proofpoint.com/v2/url?u=http-3A__darren.ankney-40gmail.com&d=DwICAg&c=euGZstcaTDllvimEN8b7jXrw

Re: [Kea-users] Kea DHCP forensic logging

2025-01-28 Thread Jim Springsteen
dpgnVfiiMM&r=eCjTemB5sg6isrvXubUeohlcjyd3d-BSpS2k69PYabI&m=nNs75CJrmipC9uj3o92Bphlar4j-AjnDtrIvexnKk8e9RtceaxgN3Ek5NJwFKjc_&s=vEWhZwXUHXKIXNAjOUG6E06cItvpVJoio5lABUSumNU&e=> To: "Kea user's list" Subject: Re: [Kea-users] Kea DHCP forensic logging Message-ID: Conte

Re: [Kea-users] Kea DHCP forensic logging

2025-01-23 Thread Darren Ankney
Hi Jim, Could you provide a .pcap file showing the DORA exchange from some client that contains this option 82 data? I would like to see what is different. It should look something like this: 2025-01-23 17:58:28 UTC Address: 192.168.20.113 has been assigned for 8 hrs 0 mins 0 secs to a device

Re: [Kea-users] Kea DHCP forensic logging

2025-01-21 Thread Jim Springsteen
Darren, I appreciate your response. I did follow the example and this is what I have in my config: "hooks-libraries": [ { "library": "/usr/lib/x86_64-linux-gnu/kea/hooks/libdhcp_legal_log.so", "parameters": { "path": "/var/log/kea",

Re: [Kea-users] Kea DHCP forensic logging

2025-01-18 Thread Darren Ankney
Hi Jim, This should be very easy to configure as the default mode of the forensic logging hook is to log option 82 data if present. The hook is documented here: https://kea.readthedocs.io/en/kea-2.6.1/arm/hooks.html#libdhcp-legal-log-so-forensic-logging A very simple configuration which should d

[Kea-users] Kea DHCP forensic logging

2025-01-17 Thread Jim Springsteen
I have purchased the premium hooks from ISC and now wanting to make use of the forensic logging. I am trying to setup to use the option 82 information that the server receives from a DHCP discover to do a couple of things. 1st I need it to be in human readable form so that I can determine how t