Arpwatch SMTP configuration

6

One of the more obscure sources of information when configuring arpwatch is arpwatch SMTP configuration.  There are so many flavors of linux and SMTP servers, how can you easily setup a vanilla SMTP mechanism to shoot out your arpwatch notifications?

In the second part of the arpwatch series (see part 1 here), I wanted to share with you guys what I used to get arpwatch notifications up and running as well as send the notification emails to my gmail account using port 587.

arpsmtp01 Arpwatch SMTP configuration

Arpwatch SMTP Configuration

SSMTP

The easiest small footprint SMTP engine I found for my Ubuntu installation was SSMTP.  You can install SSMTP by the following command in Ubuntu:

Once you have installed SSMTP, we need to edit the config file located at:

Below is a sample configuration that you might see for Gmail:

Setting up accounts:

Then to map local system accounts to the email addresses they need to send to:

A sample of how your file might look:

Testing:

To test mailflow using SSMTP, you can use the following command:

Note if you are running this in Ubuntu, you may need to install the mailutils package by running the following:

Once you install mailutils and run the test script above, you should receive your test email.  Keep in mind that you will need to make sure that your firewall rules allow outbound port 587.

Once you receive the test email, you are ready to configure arpwatch for sending to your Gmail account.

Arpwatch config

Edit the following file:

Add your config for your interface, subnet, and email address you want to send to:

After following the steps above – installing SSMTP, configuring, arpwatch, and configuring, you should be able to receive notifications for new hosts/changed MAC/IP mappings on your networks:

How does Arpwatch know to use ssmtp for sending email?

If you don’t see anything in the config file above specifying the use of ssmtp, you are correct.  Arpwatch inherently will use the program specified at the /usr/sbin/sendmail symlink (this is location in Ubuntu).  After installing ssmtp, you can edit the /usr/sbin/sendmail symlink and you will see it populated with ssmtp.  Each time it attempts to send email, it utilizes the symlink and executes ssmtp to send email.

Final Thoughts

Arpwatch is a great tool for monitoring network traffic.  The most tricky part is arpwatch smtp configuration.  Hopefully the above steps will help to get your configuration up and running and monitoring MAC/IP quickly.

Part 1 – Arpwatch Home Network Monitor