Achieving RFC 1918 coverage

View as Markdown

Scanning the entire RFC 1918 private address space can turn up subnets or assets you did not know were on your internal network. RFC 1918 is an internet standard published by the Internet Engineering Task Force (IETF) that defines best practices for private networking and reserves three address ranges for private use:

  • 10.0.0.0/8 or 10.0.0.0 - 10.255.255.255
  • 172.16.0.0/12 or 172.16.0.0 - 172.31.255.255
  • 192.168.0.0/16 or 192.168.0.0 - 192.168.255.255

Who is this playbook for and why?

This playbook is for runZero administrators who want to run discovery scans across the entire RFC 1918 private address space.

runZero’s Full RFC 1918 discovery scan option discovers assets across all three private address ranges as a single task. That option is only recommended for small networks with limited complexity and a single-site configuration. Use this playbook for more advanced scenarios or larger, more complex networks.

How will runZero help?

runZero can discover subnets or assets you may not have known about by scanning the entire RFC 1918 private address space. That coverage can help you confirm that your asset inventory is complete.

What will I need to do?

To scan the entire RFC 1918 private address space, you will:

  1. Determine how to divide the private address ranges.
  2. Create a scan template for each address range.
  3. Configure each scan.
  4. Review the RFC 1918 coverage report.

Steps to implement

Follow these steps to run custom RFC 1918 scans across your network.

Step 1: Determine how to divide the private address ranges

A full RFC 1918 scan across a large network can take days or even weeks to complete, so break the scan into multiple tasks. Finding the right balance for your organization may take some trial and error. One option is to split the scan into six sections:

Discovery Scope IP Address Range No. of IP Addresses
192.168.0.0/16 192.168.0.0 - 192.168.255.255 65,536
172.16.0.0/12 172.16.0.0 - 172.31.255.255 1,048,578
10.0.0.0/10 10.0.0.0 - 10.63.255.255 4,194,304
10.64.0.0/10 10.64.0.0 - 10.127.255.255 4,194,304
10.128.0.0/10 10.128.0.0 - 10.191.255.255 4,194,304
10.192.0.0/10 10.192.0.0 - 10.255.255.255 4,194,304

Step 2: Create an RFC 1918 scan template

You will run multiple scans to cover all of the RFC 1918 private address ranges. A scan template simplifies scheduling them and helps keep the configuration consistent across each scan.

  1. Add a template by selecting Tasks > Task library in the side navigation and clicking Add template.
  2. Enter a Name for the template.
  3. Set the Scan rate to at least 5,000 packets per second.
On high-speed wired networks, a scan rate of 10,000 or more can shorten the time a scan takes to complete.
  1. Open the Advanced configuration tab.
  2. Under Excluded hosts, exclude every subnet that other tasks already scan. Adding “scan:scope” to Excluded hosts also excludes all assets already defined in your registered subnets.
  3. Under Subnet sampling, enable Only scan subnets with active hosts and set an appropriate Sample rate and Subnet size.
    • The sample rate is the percentage of addresses in each subnet that are prescanned to decide whether the subnet should be scanned.
    • The subnet size is the number of IP addresses in each subnet.
    • By default, the subnet size is 256 addresses (a /24 subnet) and 3% of the addresses in each subnet are prescanned.
    • If several scans at the default 3% sample rate still miss assets, you can increase it. A higher sample rate also means a longer scan runtime, so an increase from 3% to 5% is a reasonable first step.
    For your first RFC 1918 scan, runZero recommends the default sample rate of 3% and the default subnet size of 256.
  4. Save your template.

Step 3: Configure each of the RFC 1918 scans

With the template saved, schedule a scan for each range you identified in Step 1.

  1. Create a new scan task by selecting Tasks in the side navigation and clicking Scan > Template scan.
  2. Type the name of the RFC 1918 scan template you just created into the search bar.
  3. Select the radio button for the appropriate template and click Continue to scan configuration.
  4. Enter a Scan name.
  5. Set the Discovery scope to the first RFC 1918 address range from Step 1.
  6. Set the Start time to when you want the scan to start.
  7. Click Initialize Scan.
  8. Repeat these steps to schedule each of the remaining RFC 1918 scans from Step 1.
Give each scan enough time to complete before the next one starts. If this is your first RFC 1918 scan, runZero recommends scheduling the scans one at a time so you can measure how long each takes. Those times help you set a schedule for any recurring scans.

Step 4: Review the RFC 1918 coverage report

When all of the RFC 1918 scans have finished, review the RFC 1918 coverage report. It shows which IPv4 subnets contain assets. After a full set of RFC 1918 scans, no subnet should be highlighted with a red box, which marks unscanned assets. Use the report to schedule recurring scans of the subnets that contain live assets. The Subnet Utilization report also finds subnets with live assets, and it exports to CSV for further analysis and for scheduling recurring scans.

Other considerations

  • If you plan to run recurring RFC 1918 scans, consider a dedicated Explorer or an Explorer with Max concurrent scans set to at least 2 so that other scan tasks can complete while the RFC 1918 scan is still running. Running multiple concurrent scans on a single Explorer may require system resources above the minimum system requirements.

  • An Explorer can have a max concurrent scans setting greater than 1, but runZero processes the results of those tasks one at a time. Processing the results of a large RFC 1918 scan can take a long time, depending on the size of the result set, and that could delay the processing and completion of other tasks.

  • Beyond RFC 1918 scanning, a couple of other options can find gaps in your scanning. Identifying gaps in scanning covers those techniques.

Getting help

For help building out this process, book a session with a runZero Customer Success Engineer.

Updated