ArpWatch is an opensource tool that monitors ethernet or FDDI network activity in the network and maintains a database of IP Address to MAC address mappings. Arpwatch notify via email if there is a change. Arpwacth is most commonly used to detect ARP Spoofing security issues in the network. Arpwatch can run on most of the Linux distributions,UNIX and Sun Solaris.
Arpwatch uses libpcap, a system-independent interface for user-level packet capture and should be installed before installing arpwatch. Arpwtch relies on the resolver library (/etc/resolv.conf) for hostname resolutions. It is important that Arpwatch is installed is installed in the same directory of lipcap.
Arpsnmp is a part of the package which very much similar to arpwatch but it is not dependent on libcap and uses snmp to collect the ip to MAC address mappings. Arpsnmp uses a script called arpfetcher to perform snmpwalks and collect data. The script can get the MAC address table data from cisco switches. All it needs is the IP address and the community name for the switch.
Installing Arpwatch requires
libcap prevously installed
ANSI C compiler (GNU compiler is fine)
Once, libcap is installed edit the makefile.in file and modify the BINDEST and MANDEST paths to that of libcap. This will ensure that arpwatch is installed in the same directory as libpcap. However, if you install only arpsnmp and libpcap is not required.
Run the configure script.
Once the config file runs without any error,
Run the make scripts to install Arpwatch
If you need to install only arpsnmp then simply run
# make arpsnmp
This creates a new arp.dat file (if there isn't one already). Because a new file is created, there will be a host of notification emails flying on a busy subnet. Hence, for the first time start with -d switch to avoid these emails.
If you are using Arpsnmp then there is a script called bihourly.sh which can be used as a cronjob. This needs you to create a file with hostnames and community name.
Another useful script is arp2ethers which can conver a arp.dat file to ethers format.
Arpwatch (includes arpsnmp) can be downloaded from here