Warda-DNSDocs v0.6.7

What lets devices go around Warda without anyone knowing, checked every 5 minutes (task network.checks, the first 2 minutes after start) and shown in Network → Network analysis (card Network check, Check again), in the assistant (step of the box, after Check), and on the dashboard of the administrators (a warning with a link: the IPv6 bypass, and the silent machines placed in no group — the computers and phones; a TV or a printer with a DNS of its own is only listed on the page). GET /api/v1/network/checks (administrators) gives:

  • ipv6: state — bypass (a router announces another DNS server than Warda, or this machine got one: the devices ask it first, or as well), dhcpv6 (a default router sets the flag M or O without announcing a DNS server: its DHCPv6 may give one), ok (IPv6 without another server), none (no IPv6 router heard) or unknown (the watch cannot run: IPv6 off on this machine, a container without the network of the host) —; watch (running, interface, since, last_asked, error); routers (each router heard: addr link-local, mac from the source link-layer option, else the neighbour table, lifetime as default router in seconds, managed, other, dns announced (RDNSS), search (DNSSL), prefixes, first, last, and from Warda foreign (the DNS servers that are not Warda), vendor (IEEE registry), label and device_id (the machine of the network with this hardware address, the model of the box for the gateway), gateway); resolvers (the IPv6 DNS servers of this machine, from resolv.conf, a bypass only when the watch cannot run: with it, a server written by hand on this machine is not one); announced (Warda announces itself, section above); own (the IPv6 addresses of Warda to give as DNS server, local ones — ULA — first, never the link-local one).
  • silent: the machines present on the network (seen in the last 45 minutes) for an hour at least without a break (no gap of more than 45 minutes between two sightings: a laptop just woken or a phone just back home asks soon enough) that asked Warda nothing for 24 hours — never the box itself, the gateway, the routers, nor the machines of the group Network equipment (switches and access points ask nothing, rightly), nor the machines ignored (below) —, computers and phones first: mac, addr, label, vendor, random_mac, device_id, first_seen, seen_at, last_query (zero: never), group; silent_known (the machines of the network can be seen), machines and using (those present, those that ask Warda; the ignored machines are not counted), at. The start of the current presence of each machine is kept (present_since of the machines of GET /api/v1/network: the time it was seen again after a gap of more than 45 minutes).
  • ignored: the machines an administrator ignores (mac, label, at), and acknowledged: the hardware addresses of the silent machines whose notice the dashboard hides.

A machine that uses a DNS of its own on purpose (a printer, a camera) is ignored with Ignore this device on its line (Network → Network analysis): it is listed apart under Devices ignored, with the date, and Stop ignoring counts it again (PUT /api/v1/network/checks/ignored/{mac} with an optional {"label": "…"}, DELETE /api/v1/network/checks/ignored/{mac}; audit network.silent.ignore and network.silent.count; 1024 machines at most). Hide until a new one appears, on the notice of the dashboard, hides it until a machine not in the list becomes silent (POST /api/v1/network/checks/acknowledge {"macs": [...]}, the silent machines of now; audit network.silent.hide). Both are kept in the database, for every administrator and across restarts.

The watch of the announcements (internal/ra, task network.ipv6) opens a raw ICMPv6 socket (CAP_NET_RAW) on the interface of the IPv4 default gateway, sends a router solicitation at start and every 10 minutes, and keeps what each router announces (only from a link-local address, hop limit 255; the announcements of Warda itself are left out) for its lifetime, 30 minutes at least and 24 hours at most, 32 routers at most (the one heard the longest ago gives way). An announcement without the DNS servers keeps those announced before for their lifetime (RFC 8106); a lifetime of 0 withdraws them. A router that announces another DNS server is told once a week for the same router and servers: notice network.ipv6dns (router|dns,dns|mac|label, Alerts, group of the bypasses, severity 5 in the SIEM export) and a warning in the log. The watch and the reading of the DHCP requests need the network of the host (the Debian package, the image, Docker with network_mode: host): in a bridged container the state is unknown and no request arrives.

The names of the phones. A phone or a tablet with a private address (random hardware address) gives no maker. When Warda is not the DHCP server of the network, it reads the requests the devices broadcast to the DHCP server of the box when they join (port 67, nothing answered; tried again every 10 minutes when the port is taken, and given back while Warda looks for another DHCP server before turning its own on): the name (option 12, the network name of a device that has none yet — a request can carry the hardware address of another device, so it never replaces one) and the class of the client (option 60: android-dhcp-… → Android, MSFT… → Windows); a name heard before the device asked Warda is kept 24 hours and given to it once it does. Else the system shows in the names it asks by itself, and no other system asks (internal/classify, devices.Systems, from the journal): captive.apple.com, mesu.apple.com, gdmf.apple.com → Apple; connectivitycheck.gstatic.com, connectivitycheck.android.com → Android (not android.clients.google.com, asked by Chrome on a computer), then its maker from its services (OnePlus, Samsung, Xiaomi, Huawei, Motorola, realme, OPPO: a strong mark replaces the cloud of OPPO, shared by OnePlus and realme); www.msftconnecttest.com, *.wns.windows.com → Windows; connectivity-check.ubuntu.com, nmcheck.gnome.org → Linux. The first system found stays (system of the device: apple, android, android/oneplus, windows, linux); only the maker of an Android phone is learnt after it. The label of a device with no name, no network name and no maker is then Apple device (10.0.4.186), Android phone, OnePlus (10.0.4.197), Windows computer (…) or Linux computer (…) — the interface translates these labels and Private address (…).