Solved

how to track tcp/ ip change in window xp

Posted on 2009-05-13
5
280 Views
Last Modified: 2012-05-06
sir,

one user use my static ip. we identify them. he change the ip to private ip. we go to event viewer to track the ip change in system event viewer. but he also delete the event viewer item also. Now how can i found when ip change. pls tell us

thanks

0
Comment
Question by:Manojtanwar
  • 2
  • 2
5 Comments
 
LVL 19

Assisted Solution

by:PeteJThomas
PeteJThomas earned 120 total points
ID: 24373523
Sorry but I know of no way to do this at all.

I don't even think there is an event logged when you change IP addresses in the first place?
0
 
LVL 6

Accepted Solution

by:
MikeGGG earned 360 total points
ID: 24373571
You can write a small script which should constantly (for example once in a minute or in ahour)  resolve the DNS/Netbios name of his PC to IP, and compare with a previous lookup result. When it changed - its up to you to set up a trigger. For example - an email or so.
0
 
LVL 6

Assisted Solution

by:MikeGGG
MikeGGG earned 360 total points
ID: 24373612
or, much better, remove him from local admins group. I just cannot imagine that  users will change their IPs or delete event logs and the administrator must tolerate it.
0
 
LVL 19

Assisted Solution

by:PeteJThomas
PeteJThomas earned 120 total points
ID: 24373711
==> or, much better, remove him from local admins group. I just cannot imagine that  users will change their IPs or delete event logs and the administrator must tolerate it. <==

Agreed!!

I may have misunderstood the question, I was assuming you meant you need to know when it was last changed rather than how to audit this change moving forward... O.o

Pete
0
 
LVL 7

Assisted Solution

by:sfarazmand
sfarazmand earned 20 total points
ID: 24374545
And to add, any alteration of company equipment to include computers is normally in violation of security training or documents the user signed.  If the user is consistently in the wrong, those policies can be used to terminate (make unemployed, not...well...you know) them.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question