Initial network scans

View as Markdown

Background

Once you have an Explorer installed, you can start network discovery. The end goal is scheduled scans you set and forget, but the first scans deserve a more structured approach.

Use your first scans to:

  • Verify the Explorer is set up properly and has everything installed
  • Validate Explorer connectivity to different parts of the network
  • Learn how long scans of different sizes take, which helps with future scheduling

Your first few scans

Start small to confirm everything works as expected: a few /24 network blocks from each of the RFC 1918 ranges.

To set up the first scan:

  1. Go to Sites > New Site > Create a new temporary site within the Organization
  2. Go to Tasks > Scan > Standard Scan to create a scan task
  3. Choose the new site you created in step 1
  4. In the Discovery Scope, include a range of RFC1918 IP addresses plus a small network or two that you know is in use. A suggested RFC1918 range:
    10.0.0.0/24,10.0.255.0/24,10.64.0.0/24,10.64.255.0/24,10.128.0.0/24,10.128.255.0/24,
    10.192.0.0/24,10.192.255.0/24,10.255.0.0/24,10.255.255.0/24,192.168.0.0/24,192.168.64.0/24,
    192.168.128.0/24,192.168.192.0/24,192.168.255.0/24,172.16.0.0/24,172.23.0.0/24,172.31.0.0/24,
    <your networks here>
    
  5. On the Advanced tab, enable the Subnet sampling option
  6. Click Initialize Scan

When these scans complete, check the following:

  • Check the ipv4.traceroute value for assets in each RFC1918 range to verify you aren’t sending traffic to an edge router or firewall.
    • Unused private IPs should have stubbed-out routes so traffic doesn’t go to the default gateway, which can create a loop. Traceroutes from the Explorer can also verify this.
  • If your scan results show a long run of roughly sequential IPs with only ICMP or a few of the same ports open, that’s probably a proxy or firewall. Check those IPs to see if any are real. To find assets with only ICMP enabled, use the inventory query alive:t AND service_count:=1 AND service_count_icmp:=1
    • You can add an allow rule for the Explorer IP to scan the devices on the other side properly
    • Or add a second Explorer on the other side of the proxy or firewall
  • If you get reports or alerts about service outages, look for session-aware devices such as routers, firewalls, and proxies struggling with the session load. If you run into this, you have a couple of options.
    • The simplest fix is another Explorer on the other side of the device, running its own scans
    • Or segment your scans on the existing Explorer: run smaller, separate scan tasks for the network ranges on the other side of the device, with lower packets per second and max group sizes so fewer IPs are scanned at once
  • Check how long each scan took to estimate how long larger scans would take
  • Verify you see screenshots on ports that accept HTTP/HTTPS requests
    • If you don’t see any, you likely need to install Chrome on the machine
  • Check for MAC addresses
    • If you aren’t seeing them, configure SNMP
    • If SNMP is configured, verify the community strings and check for unmanaged switches
Once your first scan has run successfully, you can delete the temporary site and set up a real scan.

Full RFC 1918 scans

After the initial test scans, expand scanning to cover every subnet with live assets. One way to find all of them is a full RFC 1918 scan.

The Full RFC 1918 discovery scan option discovers assets across these private address ranges in a single task:

  • 10.0.0.0/8 or 10.0.0.0-10.255.255.255
  • 172.16.0.0/12 or 172.16.0.0-172.31.255.255
  • 192.168.0.0/16 or 192.168.0.0-192.168.255.255
The Full RFC 1918 discovery scan option is recommended only for small networks with limited complexity, and only in a single site configuration.

In a large, complex network, a single scan of the entire RFC 1918 private address space can take days, if not weeks. For more on scanning the full RFC 1918 space, runZero recommends the Achieving RFC 1918 coverage playbook.

Once you’ve scanned your private address space, review Identifying gaps in scanning for the built-in reports that help you understand your network coverage.

Updated