in More Search Options

Threat list and Continuous Scan

Last post 04-29-2008 11:46 AM by Swan. 3 replies.
Page 1 of 1 (4 items)
Sort Posts:
  • 02-29-2008 1:30 PM

    • borgan
    • Top 50 Contributor
    • Joined on 08-16-2007
    • Posts 184
    • Points 441

    Threat list and Continuous Scan

    I want to be sure I understand the Threat list as it is used with continuous scan in LANsurveyor.

     

    Let’s say an open map is being continuously scanned for the addition of rogue devices. Then a device that has already been mapped is disconnected from the network, LS scans the network, then the device is reconnected to the network.

     Will LS detect it as a rogue device and add it to the Threat list, or is that determined by the settings on the Continuous Scan, Criteria tab?
    • Post Points: 3
  • 02-29-2008 6:14 PM In reply to

    • Haley
    • Top 25 Contributor
    • Joined on 01-23-2003
    • USA
    • Posts 443
    • Points 2,001
    • Moderator
      SolarWinds Employee

    Re: Threat list and Continuous Scan

    When a new device (a device that is not on the map and not part of the Threat List) is found through Continuous Scan, the item is added to the Threat List.  A device that has been mapped will not go into the Threat List if the device is not found in subsequent scan even if it is found again in later scan. 

    Haley Oyler
    Project Manager
    SolarWinds
    • Post Points: 3
  • 04-29-2008 3:17 AM In reply to

    • Arcastor
    • Not Ranked
    • Joined on 04-10-2008
    • Posts 7
    • Points 17

    Re: Threat list and Continuous Scan

    I was thinking that even if a device has been ever mapped one time, it could be on the threat list: for example if that device changed switch port connection or switch address (and options correctly checked).

     Something that I noticed: if connect a new device which is detected is threat list. I changed IP address and switch port connection. Continuous scan update the switch port connection but on the old IP address. So if I try to "find node", LS is unable to find my node with new IP address. Is is normal?
     

    About Continuous Scan, I have also one question: what is the difference between threat with a green ticket and a red exclamation? Green ticket for authenticated nodes or node ever been mapped?

    A feedback about Continuous scan: I think that a delete button or a button to change status to "Approved node" or "Authenticated node" would be great. Delete button is not intuitive for all.
     

    • Post Points: 3
  • 04-29-2008 11:46 AM In reply to

    • Swan
    • Top 500 Contributor
    • Joined on 06-19-2007
    • Lafayette, CA USA
    • Posts 29
    • Points 61

    Re: Threat list and Continuous Scan

     Hi Arcastor,

    You are correct: an existing node on a map can be added to the Threat List. Your example is a good one: depending on how options are set in Continuous Scan, if a node changes its Layer 2 connectivity (changes switches or switch ports), it can be added to the Threat List.

    Regarding the green check or red exclamation, I think you are referring to the icons at the far left of a Threat List entry (to the left of the Node Name). These icons indicate whether a node is authenticated or not. By default, the authentication methods are via the LANsurveyor Responder and SNMP. Click the Options button in the Continuous Scan window, then select  "IP Node Responses" tab to select additional authentication methods.

    Finally, thanks for your feedback regarding Delete/Approve button. 

    Michael Swan
    Network Discovery and Visualization
    SolarWinds
    • Post Points: 1
Page 1 of 1 (4 items)