Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring Network Scans and Subnet Scans
Configuring Network Scan operations consist of these major tasks:
1. Create the external accounts of Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , or SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. type for network hosts and devices. For details, see Adding External Accounts.
2. Add the scan configurations (Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , or SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. ) needed to query all the devices in the target network. For details, see:
Configuring the Networks/Subnets for WMI Scan Type
Configuring the Networks/Subnets for SNMP Scan Type
Configuring the Networks/Subnets for SSH Scan Type
The Domain/WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification., SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. , and SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. credentials are used during a network scan or a subnet Subnet is the logical division of an IP network. scan to profile Windows servers and machines (WMI Windows Management Instrumentation. WMI consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification. credentials), Linux servers and machines (SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. credentials), and network devices (SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. ).
3. After running a network scan, import the discovered network devices into Policy Manager (see Monitoring Discovered Devices).
4. Review the set of discovered devices and view the connected endpoints and neighbors (see Monitoring Discovered Devices).
Configuring a Network Scan
Seed devices are the initial IP addresses provided by the network administrator to start the network scan. When you initiate a network scan and specify the seed devices, network discovery uses SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. to:
Find any other devices connected to the seed devices.
Profile the connected devices.
Policy Manager uses that information to detect more devices in the network. The network discovery scan will proceed to the network depth specified by the parameter (described in Table 1 below).
You can go to those devices and see their neighbor devices.
|
|
Running a network scan on seed devices is a time- and resource-consuming operation. Depending on the number of devices associated with the seed device, a complete scan can take more than an hour. |
To configure a network scan:
1. Navigate to >. The page opens.
Figure 1 Network Scan Page
2. Click the link. The dialog opens.
Figure 2 Configuring a Network Scan
3. Specify the parameters as described in the following table:
|
Parameter |
Action/Description |
|
Scan Type |
Select . For scan operations to be operable, the parameter must be configured. The primary ClearPass server in a zone distributes the load among other Policy Manager nodes in the zone. For details, see Server Role in Zone. |
|
Zone |
Specify the ClearPass Zone (for more information, see Managing Policy Manager Zones). If Policy Manager Zones have not yet been set up, accept the zone. The primary server in the zone forwards the scan request to the other Policy Manager nodes in the zone, depending on the seed device. Each scan configuration added is distributed by the server to a different node in the zone. If one scan configuration has multiple seed devices, all the seed devices are forwarded to one node. |
|
Seed Devices |
Enter the IP addresses of one or more seed devices from which the network scan should proceed. Separate multiple device IP addresses with commas. |
|
Frequency of Scan |
Specify the frequency of the network scan: On Demand This option runs the network scan once, either immediately if no start time is specified, or at the time specified by the parameter. Hourly Daily |
|
Scan Depth |
Specify the by selecting the desired number from to . The Scan Depth numbers indicate the levels of the network you want to scan. The default is. The seed devices are, by default, at . Starting from the seed device, the next device level is , and so on, until the scan reaches the scan depth specified here. |
|
Probe ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries |
The ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. (Address Resolution Protocol) table provides information about MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address and IP address associations for endpoints that were discovered by this Policy Manager server. The ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries for the specified network(s) are read irrespective of whether this check box is enabled. When this option is enabled, Policy Manager uses the ARP Address Resolution Protocol. ARP is used for mapping IP network address to the hardware MAC address of a device. entries to discover network access devices (NADs), then proceeds to perform a network scan to the configured scan depth. |
4. Click . You return to the Network Scan page. The status of the network scan operation shows initially as Running, and finally, Completed. The green status indicator indicates that the scan operation was successful.
5. To restart a completed scan, click the green button.
Configuring a Subnet Scan
To configure a subnet Subnet is the logical division of an IP network. scan:
1. Navigate to >. The page opens.
Figure 3 Network Scan Page
2. Click the link.
The dialog opens.
Figure 4 Configuring a Subnet Scan
3. Specify the parameters as described in the following table:
4. Click . You return to the Network Scan page. The status of the subnet Subnet is the logical division of an IP network. scan operation shows initially as Running, and finally, Completed. The green status indicator indicates that the scan operation was successful.
Figure 5 Seed Devices Successfully Scanned
Viewing Details About a Subnet Scan
Additional information is available for the configured subnet Subnet is the logical division of an IP network. scans. To view details about a subnet scan, navigate to > > .
Configuring Nmap-Based Endpoint Port Scans
The network scan feature supports running an Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. (Network Mapper)-based scan on a host to detect open ports and also to fingerprint the services running behind those ports. This information is used in the device profile.
To configure endpoint port scans using Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on.:
1. Enable Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on.-based endpoint port scans.
a. Navigate to > > > . The page opens.
b. Select the tab.
Figure 6 Cluster-Wide Parameters > Profiler Dialog
c. Set the parameter to , then click .
For more information, see Profiler Parameters.
|
|
Setting this value to TRUE enables active scan of the host for open ports. This can be resource intensive. Also, the value is ignored when Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. scan is enabled. |
2. Schedule a network scan configuring a seed device with entries enabled (see Configuring a Network Scan).
3. When the network scan is completed, select an endpoint (see Adding and Modifying Endpoints).
a. Navigate to > > .
b. From the page, click the endpoint of interest. The page opens.
Figure 7 Edit Endpoint Page
4. To view the list of host services and the list of open ports returned by the network scan for the selected host or endpoint, select the tab.
The > page shows the fingerprint details that include Nmap Network Mapper. Nmap is an open-source utility for network discovery and security auditing. Nmap uses IP packets to determine such things as the hosts available on a network and their services, operating systems and versions, types of packet filters/firewalls, and so on. scan data.