I have CIFS server joined to the domain. I would like to check if someone is connecting to CIFS server via IP address instead of DNS name.
My idea is to:
1. add additional IP address from the same VLAN and change the DNS entry to point to the new_IP_address.
2. after that check if someone (and who) is accessing NetApp CIFS server via old_IP_address
The question is: how Can i proceed with step number 2? Can I somehow filter out who is accessing the CIFS shares per interface?
OK I think I have an answer
netstat -d will show all the active connections with the interface. I'm still not sure from where netstat resolve the name of the interface, is it from AD or /etc/hosts?
I guess it depends on /etc/nsswitch.conf but if somone can confirm that would be great