What lets devices go around Warda without anyone knowing, checked every 5
minutes (task network.checks, the first 2 minutes after start) and shown
in Network → Network analysis (card Network check, Check
again), in the assistant (step of the box, after Check), and on the
dashboard of the administrators (a warning with a link: the IPv6 bypass,
and the silent machines placed in no group — the computers and phones; a
TV or a printer with a DNS of its own is only listed on the page). GET /api/v1/network/checks (administrators) gives:
ipv6:state—bypass(a router announces another DNS server than Warda, or this machine got one: the devices ask it first, or as well),dhcpv6(a default router sets the flag M or O without announcing a DNS server: its DHCPv6 may give one),ok(IPv6 without another server),none(no IPv6 router heard) orunknown(the watch cannot run: IPv6 off on this machine, a container without the network of the host) —;watch(running,interface,since,last_asked,error);routers(each router heard:addrlink-local,macfrom the source link-layer option, else the neighbour table,lifetimeas default router in seconds,managed,other,dnsannounced (RDNSS),search(DNSSL),prefixes,first,last, and from Wardaforeign(the DNS servers that are not Warda),vendor(IEEE registry),labelanddevice_id(the machine of the network with this hardware address, the model of the box for the gateway),gateway);resolvers(the IPv6 DNS servers of this machine, fromresolv.conf, a bypass only when the watch cannot run: with it, a server written by hand on this machine is not one);announced(Warda announces itself, section above);own(the IPv6 addresses of Warda to give as DNS server, local ones — ULA — first, never the link-local one).silent: the machines present on the network (seen in the last 45 minutes) for an hour at least without a break (no gap of more than 45 minutes between two sightings: a laptop just woken or a phone just back home asks soon enough) that asked Warda nothing for 24 hours — never the box itself, the gateway, the routers, nor the machines of the group Network equipment (switches and access points ask nothing, rightly), nor the machines ignored (below) —, computers and phones first:mac,addr,label,vendor,random_mac,device_id,first_seen,seen_at,last_query(zero: never),group;silent_known(the machines of the network can be seen),machinesandusing(those present, those that ask Warda; the ignored machines are not counted),at. The start of the current presence of each machine is kept (present_sinceof the machines ofGET /api/v1/network: the time it was seen again after a gap of more than 45 minutes).ignored: the machines an administrator ignores (mac,label,at), andacknowledged: the hardware addresses of the silent machines whose notice the dashboard hides.
A machine that uses a DNS of its own on purpose (a printer, a camera) is
ignored with Ignore this device on its line (Network → Network
analysis): it is listed apart under Devices ignored, with the date,
and Stop ignoring counts it again (PUT /api/v1/network/checks/ignored/{mac} with an optional {"label": "…"},
DELETE /api/v1/network/checks/ignored/{mac}; audit
network.silent.ignore and network.silent.count; 1024 machines at
most). Hide until a new one appears, on the notice of the dashboard,
hides it until a machine not in the list becomes silent (POST /api/v1/network/checks/acknowledge {"macs": [...]}, the silent machines
of now; audit network.silent.hide). Both are kept in the database, for
every administrator and across restarts.
The watch of the announcements (internal/ra, task network.ipv6) opens a
raw ICMPv6 socket (CAP_NET_RAW) on the interface of the IPv4 default
gateway, sends a router solicitation at start and every 10 minutes, and
keeps what each router announces (only from a link-local address, hop
limit 255; the announcements of Warda itself are left out) for its
lifetime, 30 minutes at least and 24 hours at most, 32 routers at most (the
one heard the longest ago gives way). An announcement without the DNS
servers keeps those announced before for their lifetime (RFC 8106); a
lifetime of 0 withdraws them. A router that announces another DNS server is
told once a week for the same router and servers: notice network.ipv6dns
(router|dns,dns|mac|label, Alerts, group of the bypasses, severity 5
in the SIEM export) and a warning in the log. The watch and the reading of
the DHCP requests need the network of the host (the Debian package, the
image, Docker with network_mode: host): in a bridged container the state
is unknown and no request arrives.
The names of the phones. A phone or a tablet with a private address
(random hardware address) gives no maker. When Warda is not the DHCP server
of the network, it reads the requests the devices broadcast to the DHCP
server of the box when they join (port 67, nothing answered; tried again
every 10 minutes when the port is taken, and given back while Warda looks
for another DHCP server before turning its own on): the name (option 12,
the network name of a device that has none yet — a request can carry the
hardware address of another device, so it never replaces one) and the class
of the client (option 60:
android-dhcp-… → Android, MSFT… → Windows); a name heard before the
device asked Warda is kept 24 hours and given to it once it does. Else the
system shows in the names it asks by itself, and no other system asks
(internal/classify, devices.Systems, from the journal):
captive.apple.com, mesu.apple.com, gdmf.apple.com → Apple;
connectivitycheck.gstatic.com, connectivitycheck.android.com → Android
(not android.clients.google.com, asked by Chrome on a computer), then its
maker from its services (OnePlus, Samsung, Xiaomi, Huawei, Motorola,
realme, OPPO: a strong mark replaces the cloud of OPPO, shared by
OnePlus and realme); www.msftconnecttest.com, *.wns.windows.com →
Windows; connectivity-check.ubuntu.com, nmcheck.gnome.org → Linux. The
first system found stays (system of the device: apple, android,
android/oneplus, windows, linux); only the maker of an Android phone
is learnt after it. The label of a device with no name, no network name and
no maker is then Apple device (10.0.4.186), Android phone, OnePlus (10.0.4.197), Windows computer (…) or Linux computer (…) — the
interface translates these labels and Private address (…).