Active scanning
An active scan finds every responsive device on a network, fingerprints each one, and fills the asset, services, screenshot, and software inventory. Regular scans of internal and external networks are a basic part of network management. You configure a scan by site, Explorer, and scan scope, and the scope can include IP ranges, domain names, ASNs, and even entire country codes.
A new scan has many parameters you can set, from a schedule to the advanced options below. To start one, log in to the runZero Console, select Scan from the Data sources section of the navigation menu, and choose “Start Standard Scan”. You can also launch scans from the Inventory views.
Site
runZero organizes information into organizations and sites. An organization is a distinct entity that keeps its data separate and holds a collection of sites. Sites model segmented networks, particularly independent networks that use the same private IP address ranges.
For example, you might have several physical locations, each with its own local network on the 10.0.0.0/8 private IP range. Define each one as a site with its own Explorer, and runZero treats the networks and assets as completely independent, even when similar systems appear at the same IP addresses in each.
Because scan analysis happens at the site level, the boundaries you define for a site become the default scope for its scans.
Explorer
From the Explorers registered to the site, select the Explorer that will run the scan. It must be able to communicate directly with the networks and addresses in your discovery scope, and ideally it reaches every address in the scope with no firewall in the way. Stateful firewalls and VPN gateways may interfere with discovery.
Hosted External Explorer
runZero Platform users can scan public IP space with runZero-hosted Explorers. When you create a scan, choose a Hosted External Explorer in the ‘Run task with’ dropdown. With this option, the discovery scope must use public IP addresses or ranges, or resolve to public IP space.
Discovery scope
The discovery scope defines which IP addresses the scan covers. The keyword “defaults” uses the site settings, and you can change the scope per scan as well. The scope should include at least one IP address or hostname. You can write IPv4 address ranges in most standard formats:
10.0.0.110.0.0.0/2410.0.0.0/255.255.255.010.0.0.1-10.0.0.255
You can specify individual IPv6 addresses, but not IPv6 ranges.
Hostnames in the scope are resolved at runtime by the assigned Explorer. If a hostname resolves to multiple IP addresses, the scan covers all of them. A hostname can also carry a mask, which expands around each resolved address. For example, if example.com resolves to both 1.2.3.4 and 5.6.7.8, the input example.com/24 becomes 1.2.3.0/24 and 5.6.7.0/24. IPv6 addresses returned from hostname resolution are scanned if the Explorer has a valid IPv6 address and a route to the target.
Discovery keywords
These keywords work in both scan scopes and exclusions.
-
asn4 selects the IPv4 ranges associated with a given AS number:
asn4:<AS number>. -
country4 selects the IPv4 ranges associated with a given two-character country code:
country4:<ISO code>. -
public and private select the IPv4 and IPv6 addresses of assets in the current organization:
public:<mode>andprivate:<mode>. Set the mode toall,primary, orsecondaryto choose which IP addresses are used. Thepublickeyword selects all non-reserved IP addresses on organization assets, and theprivatekeyword selects all RFC-1918 and private use IP addresses on organization assets. -
domain automatically selects the publicly-known hostnames for a given domain name:
domain:<domain name>. Thedomain:<domain>keyword is available to cloud-hosted users.
Scan name
Give your scan task a name so it’s easier to track.
Scan speed
Set the maximum packet rate for the whole discovery process, in network packets per second. 500 is conservative, 3000 works for most LANs including WiFi, and 10000 or more may help large sites with fast connectivity.
Scan speed directly affects how long the scan takes. An approximate formula:
time in seconds = hosts x ports x attempts / scan speed
The discovery scope mostly determines the number of hosts. The number of ports is around 500 by default, and the scan makes three connection attempts.
The advanced scan options can change the number of hosts and ports scanned, and the maximum host rate and group size can also affect speed; see the advanced scan options below.
The formula leaves out the time spent taking screenshots, following web server redirects, and processing the scan data.
Schedule
You can set a date and frequency for your scan task. Dates and times follow your browser’s advertised timezone.
A scan scheduled to start in the past launches immediately, then repeats at the specified time at the frequency you selected.
Scheduling grace period
Set how many hours the scan waits for an available Explorer before giving up. With a zero or negative value, the scan retries indefinitely until an Explorer becomes available.
Scan duration limit
Set a limit in hours on scan duration; if scanning is still in progress when the time runs out, runZero cancels the scan. This limit does not cover processing time.
If you set this to 0, runZero applies no limit.
Advanced scan options
On the Advanced tab you can view and change more scan settings, such as network exclusions, scan speed, the ports the TCP scan covers, and which probes are enabled. The defaults should work for most organizations but may need tuning for slow networks or unreliable links.
Maximum host rate
Beyond the overall scan rate in packets per second, you can also cap the rate at which packets go to any single host IP address. This helps when you have devices that are quick to overload under network traffic. The default should be safe for most systems.
Max group size
When runZero scans your network, it spreads the load across many IP addresses at once. The max group size sets how many IP addresses can be actively scanned at the same time, allowing for hosts that take a while to respond to probes. It needs to be at least as large as the overall scan speed, or it would hold the scan below the speed you set. If you enter a value lower than the overall scan speed, runZero raises it automatically at scan time.
Max group size is most useful with stateful network devices that can track only a limited number of connections at once, since it restricts how many active TCP sessions a runZero scan creates.
Max TTL
The IP standards define a maximum hop count for packets: the Time To Live or TTL in IPv4, and the Hop Limit in IPv6. Every device that processes a packet must decrease the TTL or Hop Limit by one, and when the value reaches zero, the router receiving the packet must discard it. Max TTL sets the maximum hop limit for scan traffic.
ToS
The IP standards define a Type of Service or ToS for packets. IPv4 calls it the Type of Service or ToS, and IPv6 calls it the Traffic Class or TC. Switches and routers use the ToS or Traffic Class to prioritize network traffic, and the lower bits of the IPv4 ToS are also used for congestion control. This option sets the ToS or Traffic Class for scan traffic. The ToS/Traffic Class setting applies only to the basic discovery probes, not to all traffic runZero sends. Some protocols, such as SNMP, and integrations, such as VMware, do not set the ToS/Traffic Class fields on their packets. If all scan traffic must carry the correct ToS or Traffic Class, tag it through settings on the managed switch port instead.
TCP ports
The Included TCP ports and Excluded TCP ports fields override the default scan ports. The string “defaults” looks up the current default port list at scan time. The current port list is:
1 7 9 13 17 19 21 22 23 25 37 42 43 49 53 69 70 79 80 81 82 83 84 85 88 102 105 109 110 111 113 119 123 135 137 139 143 161 179 222 264 280 384 389 402 407 442 443 444 445 465 500 502 512 513 515 523 524 540 541 548 554 587 617 623 631 636 664 689 705 717 743 771 783 789 830 873 888 902 903 910 912 921 949 990 993 995 998 1000 1024 1030 1035 1080 1083 1089 1090 1091 1098 1099 1100 1101 1102 1103 1128 1129 1153 1158 1199 1211 1220 1234 1241 1260 1270 1300 1311 1337 1352 1433 1434 1440 1443 1468 1494 1502 1514 1521 1530 1533 1581 1582 1583 1604 1610 1611 1723 1755 1801 1811 1830 1883 1900 1911 2000 2002 2021 2022 2023 2024 2031 2049 2068 2074 2082 2083 2100 2103 2105 2121 2181 2199 2207 2222 2224 2323 2362 2375 2376 2379 2380 2381 2404 2443 2455 2525 2533 2598 2601 2602 2604 2638 2809 2947 2967 3000 3001 3003 3033 3037 3050 3052 3057 3071 3080 3083 3128 3142 3200 3210 3217 3220 3260 3268 3269 3273 3299 3300 3306 3311 3312 3351 3389 3460 3478 3500 3502 3628 3632 3690 3780 3790 3817 3868 3871 3872 3900 4000 4092 4322 4343 4353 4365 4366 4368 4369 4406 4433 4443 4444 4445 4567 4659 4679 4730 4786 4840 4843 4848 4900 4949 4950 4987 5000 5001 5003 5006 5007 5022 5037 5038 5040 5044 5050 5051 5060 5061 5093 5094 5168 5222 5247 5250 5275 5347 5351 5353 5355 5392 5400 5405 5432 5433 5466 5498 5520 5521 5554 5555 5560 5580 5601 5631 5632 5666 5671 5672 5678 5683 5800 5814 5900 5901 5902 5903 5904 5905 5906 5907 5908 5909 5910 5911 5920 5938 5984 5985 5986 5988 5989 6000 6001 6002 6050 6060 6070 6080 6082 6101 6106 6112 6161 6262 6274 6277 6333 6379 6405 6432 6443 6481 6502 6503 6504 6514 6542 6556 6660 6661 6667 6905 6988 7000 7001 7002 7021 7070 7071 7077 7080 7100 7144 7181 7210 7373 7443 7444 7474 7510 7547 7579 7580 7676 7700 7770 7777 7778 7780 7787 7800 7801 7860 7879 7902 7990 7999 8000 8001 8002 8003 8004 8006 8008 8009 8010 8012 8014 8020 8023 8028 8030 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8095 8098 8099 8100 8123 8127 8160 8161 8172 8180 8181 8182 8188 8193 8200 8205 8222 8265 8300 8303 8333 8400 8428 8443 8444 8445 8446 8447 8448 8449 8471 8488 8500 8503 8530 8531 8545 8649 8686 8787 8800 8812 8833 8834 8850 8871 8880 8883 8888 8889 8890 8899 8900 8901 8902 8903 8983 9000 9001 9002 9042 9060 9080 9081 9084 9090 9091 9092 9099 9100 9111 9152 9160 9200 9300 9380 9390 9391 9401 9418 9428 9440 9443 9444 9471 9495 9524 9527 9530 9593 9594 9595 9600 9809 9855 9997 9998 9999 10000 10001 10008 10050 10051 10080 10098 10162 10202 10203 10250 10255 10257 10259 10443 10616 10628 10800 11000 11099 11211 11234 11333 11434 11443 12174 12203 12221 12345 12379 12397 12401 13364 13400 13500 13778 13838 14330 15200 15671 15672 16102 16443 16992 16993 17185 17200 17472 17775 17776 17777 17778 17781 17782 17783 17784 17790 17791 17798 18245 18264 18789 18881 19000 19300 19530 19810 19888 20000 20010 20031 20034 20101 20111 20171 20222 20256 20293 21047 22222 23472 23791 23943 24442 25000 25025 25565 25672 26000 26122 27000 27017 27018 27019 27080 27888 28017 28222 28784 29418 30000 31001 31099 32400 32764 32843 32844 32845 32913 33060 34205 34443 34962 34963 34964 37718 37777 37890 37891 37892 38008 38010 38080 38102 38292 40007 40317 41025 41080 41523 41524 44334 44343 44818 45230 46823 46824 47001 47002 47290 48898 48899 49152 50000 50013 50021 50051 50070 50090 50121 50505 51443 52302 52311 53282 54321 54921 54922 54923 55553 55580 57772 61614 61616 62078 62514 65002 65535
Prescan modes for large IP spaces
Sometimes you don’t know the extent of your IP space, which subnets are in use, or how many assets you have, and that can make discovery scans hard to tune for efficiency and speed. When the space is also large, like a /16 with a few thousand IPs in use, a full discovery scan can take longer because it checks more than 500 TCP ports and 15 UDP ports on every address. In these cases, you may want to tune your scan settings to prefilter ranges and IP addresses before a full scan.
runZero has two prescan modes for faster scans: subnet sampling and host ping.
Subnet sampling
To speed up scans of large subnets, turn on the “Only scan subnets with active hosts” advanced scan option. A prescan then runs against the target space to find the subnets with an active host, using heuristics runZero has collected about which addresses are more likely to respond across subnets. That lets runZero cover a large space quickly by identifying the subnets in use before it starts full probes. Every subnet found to have active hosts is then fully scanned, unless you enable host pings.
Subnet sampling has two parameters. The sample rate sets what percentage of addresses in each subnet the prescan checks to decide whether to scan the subnet. The subnet size sets how many IP addresses make up each subnet. By default, the subnet size is 256 addresses, a /24 subnet, and the prescan checks 3% of the addresses in each subnet.
Host ping
Once you know which subnets are in use, you may want to limit the full scan to addresses that answer the most common ping methods, such as ICMP and some TCP and UDP ports. With the “Limit scans to pingable hosts” advanced scan option, only hosts that respond to a ping request are fully scanned.
The runZero Explorer uses multiple protocols for ping scans:
- Conventional ICMP ping, which sends an ICMP echo request and looks for an ICMP echo reply.
- TCP ping, which sends a TCP SYN packet to a series of common ports and checks whether the host answers with RST or TCP SYN/ACK.
- UDP ping, which sends a packet to port 65535 and checks for an ICMP port unreachable response.
You can adjust the ports used for TCP and UDP ping in the LAYER2 section of the Probes and SNMP tab when you set up a scan task.
Enterprise firewalls often block ping, and hosts are often configured to ignore ping requests, so limiting scans to pingable hosts can miss assets entirely even though their IP addresses were probed. If your goal is faster scans, subnet sampling is usually the better option.
You can use subnet sampling and the pingable-host limit together, but we recommend it only as a last resort for reducing scan times.