Identifying gaps in scanning
Background
After a full network discovery scan, you can start to understand your coverage and optimize it. This guide covers the built-in reports in runZero that show your gaps in network coverage.
RFC 1918 coverage
Start with the RFC 1918 coverage report. It shows which internal IPv4 subnets you have scanned, which likely contain assets, and which are still unknown.
The scan coverage maps show every address scanned within the 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 ranges, and the legend gives the percentage of each address space you have scanned. Click into any scanned subnet to open the subnet grid for deeper asset analysis.
Identify scanned and un-scanned areas with the coverage map: Red outlines mark un-scanned addresses that runZero knows about indirectly but hasn’t scanned directly, for example when it finds a secondary IP address on a multi-homed device within a scanned subnet. The red boxes show the subnets most likely to be in use but un-scanned.
Scan missing subnets: From the coverage report, you can launch a scan for any missing subnets in a given RFC1918 block. Look for the binocular icon.
Scan missed subnets: The missing subnets appear in the scan scope with subnet ping enabled by default. Tune the scan configuration as needed for your environment.
Subnet utilization
The Subnet utilization report shows a view of your network similar to the RFC 1918 coverage report, with the emphasis on subnets that contain live assets. It lists each subnet in your site definitions with a count of live assets for that site and subnet and a utilization percentage. Live assets outside any site subnet are grouped into an inferred subnet based on the network mask size you select.
From this report, you can pivot to the asset inventory for a subnet or start a new scan of it. You can also export the results as a CSV, which helps with more complex data analysis and with scheduling recurring scans.
Network Map
The Network Map is the fastest way to spot scanning gaps. It overlays Layer-2 switch topology, Layer-3 routing, traceroute paths, and bridges in a single interactive view, and renders unmapped MACs and unscanned traceroute hops by default, so every gap shows up as a node without an asset behind it. Search and filter directly inside the map (multi_homed:t, category:OT, etc.), then click any unmapped node to see which Explorer or scan reached it and which subnet it sits in.
Switch topology
The Switch Topology report shows layer-2 link information extracted from SNMP-enabled switches. Use it to find unmapped assets and investigate why they aren’t showing up in your scans.
Configuration for this report: The Switch Topology report maps switch ports to assets from data enumerated over SNMP. Where SNMP v1 or v2 with the default public or private communities is in use, this enumeration happens automatically. You can also provide non-default communities for SNMP v1/v2/v3 in the scan configuration. Click a node in the report to expand it and show its connections.
Finding unmapped MACs: This topology view helps you see how a given asset or switch is connected, and it also gives you a data point about risk: the number of unmapped assets. An unmapped asset is a MAC address connected to a switch but not found in an ARP cache or through any of runZero’s other techniques for remote MAC address discovery.
Re-scan to properly map MAC addresses: Where a runZero agent is connected to each network segment, unmapped MACs may point to VLANs or network segments missing from the scan scope. Where runZero scans assets multiple hops away, the unmapped asset count can estimate how well the remote segment is being identified.
Unmapped MACs
For a condensed view of all unmapped MACs, use the Unmapped MACs report. It lists every unmapped MAC in your organization, organized by switch and then by port, and you can use this data the same way as the unmapped MACs data from the Switch Topology report.