Initial network scans
Background
Once you have an Explorer installed, you can start network discovery. The end goal is scheduled scans you set and forget, but the first scans deserve a more structured approach.
Use your first scans to:
- Verify the Explorer is set up properly and has everything installed
- Validate Explorer connectivity to different parts of the network
- Learn how long scans of different sizes take, which helps with future scheduling
Your first few scans
Start small to confirm everything works as expected: a few /24 network blocks from each of the RFC 1918 ranges.
To set up the first scan:
- Go to Sites > New Site > Create a new temporary site within the Organization
- Go to Tasks > Scan > Standard Scan to create a scan task
- Choose the new site you created in step 1
- In the Discovery Scope, include a range of RFC1918 IP addresses plus a small network or two that you know is in use. A suggested RFC1918 range:
10.0.0.0/24,10.0.255.0/24,10.64.0.0/24,10.64.255.0/24,10.128.0.0/24,10.128.255.0/24, 10.192.0.0/24,10.192.255.0/24,10.255.0.0/24,10.255.255.0/24,192.168.0.0/24,192.168.64.0/24, 192.168.128.0/24,192.168.192.0/24,192.168.255.0/24,172.16.0.0/24,172.23.0.0/24,172.31.0.0/24, <your networks here> - On the Advanced tab, enable the Subnet sampling option
- Click Initialize Scan
When these scans complete, check the following:
- Check the
ipv4.traceroutevalue for assets in each RFC1918 range to verify you aren’t sending traffic to an edge router or firewall.- Unused private IPs should have stubbed-out routes so traffic doesn’t go to the default gateway, which can create a loop. Traceroutes from the Explorer can also verify this.
- If your scan results show a long run of roughly sequential IPs with only ICMP or a few of the same ports open, that’s probably a proxy or firewall. Check those IPs to see if any are real. To find assets with only ICMP enabled, use the inventory query
alive:t AND service_count:=1 AND service_count_icmp:=1- You can add an allow rule for the Explorer IP to scan the devices on the other side properly
- Or add a second Explorer on the other side of the proxy or firewall
- If you get reports or alerts about service outages, look for session-aware devices such as routers, firewalls, and proxies struggling with the session load. If you run into this, you have a couple of options.
- The simplest fix is another Explorer on the other side of the device, running its own scans
- Or segment your scans on the existing Explorer: run smaller, separate scan tasks for the network ranges on the other side of the device, with lower packets per second and max group sizes so fewer IPs are scanned at once
- Check how long each scan took to estimate how long larger scans would take
- Verify you see screenshots on ports that accept HTTP/HTTPS requests
- If you don’t see any, you likely need to install Chrome on the machine
- Check for MAC addresses
- If you aren’t seeing them, configure SNMP
- If SNMP is configured, verify the community strings and check for unmanaged switches
Full RFC 1918 scans
After the initial test scans, expand scanning to cover every subnet with live assets. One way to find all of them is a full RFC 1918 scan.
The Full RFC 1918 discovery scan option discovers assets across these private address ranges in a single task:
- 10.0.0.0/8 or 10.0.0.0-10.255.255.255
- 172.16.0.0/12 or 172.16.0.0-172.31.255.255
- 192.168.0.0/16 or 192.168.0.0-192.168.255.255
In a large, complex network, a single scan of the entire RFC 1918 private address space can take days, if not weeks. For more on scanning the full RFC 1918 space, runZero recommends the Achieving RFC 1918 coverage playbook.
Once you’ve scanned your private address space, review Identifying gaps in scanning for the built-in reports that help you understand your network coverage.