Configuring Network Scans and Subnet Scans

Configuring Network Scan operations consist of these major tasks:

1. Create the external accounts of Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , or SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. type for network hosts and devices. For details, see Adding External Accounts.

2. Add the scan configurations (Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , or SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. ) needed to query all the devices in the target network. For details, see:

Configuring the Networks/Subnets for WMI Scan Type

Configuring the Networks/Subnets for SNMP Scan Type

Configuring the Networks/Subnets for SSH Scan Type

The Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , and SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. credentials are used during a network scan or a subnet Subnet is the logical division of an IP network. scan to profile Windows servers and machines (WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification. credentials), Linux servers and machines (SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. credentials), and network devices (SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. ).

3. After running a network scan, import the discovered network devices into Policy Manager (see Monitoring Discovered Devices).

4. Review the set of discovered devices and view the connected endpoints and neighbors (see Monitoring Discovered Devices).

Configuring a Network Scan

Seed devices are the initial IP addresses provided by the network administrator to start the network scan. When you initiate a network scan and specify the seed devices, network discovery uses SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention.  to:

Find any other devices connected to the seed devices.

Profile the connected devices.

Policy Manager uses that information to detect more devices in the network. The network discovery scan will proceed to the network depth specified by the Scan Depth parameter (described in Table 1 below).

You can go to those devices and see their neighbor devices.

 

Running a network scan on seed devices is a time- and resource-consuming operation. Depending on the number of devices associated with the seed device, a complete scan can take more than an hour.
It is recommended that the network scan should be done outside of normal business hours or performed on a Policy Manager node that is not servicing core authentications.

To configure a network scan:

1. Navigate to Configuration > Network Scan. The Network Scan page opens.

Figure 1  Network Scan Page

2. Click the Start Scan link. The Schedule Scan dialog opens.

Figure 2  Configuring a Network Scan

3. Specify the Schedule Scan parameters as described in the following table:

 

Table 1: Configuring Network Scan Parameters

Parameter

Action/Description

Scan Type

Select Network Scan.

NOTE: For scan operations to be operable, the Primary Server in Zone parameter must be configured. The primary ClearPass server in a zone distributes the load among other Policy Manager nodes in the zone. For details, see Server Role in Zone.

Zone

Specify the ClearPass Zone (for more information, see Managing Policy Manager Zones). If Policy Manager Zones have not yet been set up, accept the default zone.

NOTE: The primary server in the zone forwards the scan request to the other Policy Manager nodes in the zone, depending on the seed device. Each scan configuration added is distributed by the primary server to a different node in the zone. If one scan configuration has multiple seed devices, all the seed devices are forwarded to one node.

Seed Devices

Enter the IP addresses of one or more seed devices from which the network scan should proceed. Separate multiple device IP addresses with commas.

Frequency of Scan

Specify the frequency of the network scan:

On Demand

This option runs the network scan once, either immediately if no start time is specified, or at the time specified by the Start Time of Scan parameter.

Hourly

Daily

Scan Depth

Specify the Scan Depth by selecting the desired number from 1 to 5. The Scan Depth numbers indicate the levels of the network you want to scan. The default is Scan Depth 3.

The seed devices are, by default, at Scan Depth 1. Starting from the seed device, the next device level is Scan Depth 2, and so on, until the scan reaches the scan depth specified here.

Probe ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries

The ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. (Address Resolution Protocol) table provides information about MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address and IP address associations for endpoints that were discovered by this Policy Manager server. The ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries for the specified network(s) are read irrespective of whether this check box is enabled.

When this option is enabled, Policy Manager uses the ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries to discover network access devices (NADs), then proceeds to perform a network scan to the configured scan depth.

4. Click Save. You return to the Network Scan page. The status of the network scan operation shows initially as Running, and finally, Completed. The green status indicator indicates that the scan operation was successful.

5. To restart a completed scan, click the green Status button.

Configuring a Subnet Scan

To configure a subnet Subnet is the logical division of an IP network. scan:

1. Navigate to Configuration > Network Scan. The Network Scan page opens.

Figure 3  Network Scan Page

2. Click the Start Scan link.

The Schedule Scan dialog opens.

Figure 4  Configuring a Subnet Scan

3. Specify the Schedule Scan parameters as described in the following table:

 

Table 2: Configuring Subnet Scan Parameters

Parameter

Action/Description

Scan Type

Select Subnet Scan.

You can schedule multiple subnet Subnet is the logical division of an IP network. scans per zone.

To monitor subnet Subnet is the logical division of an IP network. scan progress, navigate to Monitoring > Profiler and Network Scan > Network Scan Results.

NOTE: For scan operations to be operable, the Primary Server in Zone parameter must be configured. The primary ClearPass server in a zone distributes the load among other Policy Manager nodes in the zone. For details, see Server Role in Zone.

Zone

Specify the Policy Manager Zone. If a Zone is not configured, accept the default.

IP Subnet Subnet is the logical division of an IP network.(s)

If you selected the Subnet Scan option for the Scan Type, enter the IP addresses of one or more IP subnets Subnet is the logical division of an IP network. from which the subnet Subnet is the logical division of an IP network. scan should proceed. Separate multiple IP subnets Subnet is the logical division of an IP network. with commas.

NOTE: An IPv6 subnet Subnet is the logical division of an IP network. scan only support Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. (Network Mapping), and the device classification for an IPv4 subnet Subnet is the logical division of an IP network. scan and IPv6 subnet Subnet is the logical division of an IP network. can vary based on what Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. can fetch from the device.

Frequency of Scan

Specify the frequency of the scan:

On Demand

This option runs the subnet Subnet is the logical division of an IP network. scan once, either immediately if no start time is specified, or at the time specified by the Start Time of Scan parameter.

Hourly

Daily

Start Time of Scan

Select the time you want the subnet Subnet is the logical division of an IP network. scan to start.

4. Click Save. You return to the Network Scan page. The status of the subnet Subnet is the logical division of an IP network. scan operation shows initially as Running, and finally, Completed. The green status indicator indicates that the scan operation was successful.

Figure 5  Seed Devices Successfully Scanned

Viewing Details About a Subnet Scan

Additional information is available for the configured subnet Subnet is the logical division of an IP network. scans. To view details about a subnet scan, navigate to Monitoring > Profiler and Network Scan > Network Scan Results.

Configuring Nmap-Based Endpoint Port Scans

The network scan feature supports running an Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. (Network Mapper)-based scan on a host to detect open ports and also to fingerprint the services running behind those ports. This information is used in the device profile.

To configure endpoint port scans using Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on.:

1. Enable Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on.-based endpoint port scans.

a. Navigate to Administration > Server Manager > Server Configuration > Cluster-Wide Parameters. The Cluster-Wide Parameters page opens.

b. Select the Profiler tab.

Figure 6  Cluster-Wide Parameters > Profiler Dialog

c. Set the Enable Endpoint Port Scans using Nmap parameter to TRUE, then click Save.

For more information, see Profiler Parameters.

 

Setting this value to TRUE enables active scan of the host for open ports. This can be resource intensive. Also, the Profiler Scan Ports value is ignored when Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. scan is enabled.

2. Schedule a network scan configuring a seed device with Probe ARP entries enabled (see Configuring a Network Scan).

3. When the network scan is completed, select an endpoint (see Adding and Modifying Endpoints).

a. Navigate to Configuration > Identity > Endpoints.

b. From the Endpoints page, click the endpoint of interest. The Edit Endpoint page opens.

Figure 7  Edit Endpoint Page

4. To view the list of host services and the list of open ports returned by the network scan for the selected host or endpoint, select the Device Fingerprints tab.

The Edit Endpoint > Fingerprints page shows the fingerprint details that include Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. scan data.