11-28-2023 05:56 AM - edited 12-01-2023 02:40 AM
Hi all,
my apologies if the question is very basic. I was asked to check if CP could monitor, for objectives of compliance, open ports on the devices and send reports in case we have deviation from pre-defined baselines.
I guess CP might only run, in case, a sort of netstat on each device and check if some daemons run on specific ports. Of course, from my understanding, it cannot launch a true TCP/UDP port-scanning and check the packets it gets or it doesn't get as a normal scan SW may do.
Am I correct with my reasoning or it's a no way?
In case, may DNAC play this role of checking the complaince from the point of view of open ports?
TIA,
Gio
11-28-2023 06:28 AM
Prime doe compliance report based on the information available on the device config :
most industry uses NMAP to scan the port-scan to check any Open ports against devices. (subject to you are allowed if any FW between Scanner and devices) - that is basic requirement.
DNAC also does the compliance checks :
11-28-2023 11:22 PM - edited 11-29-2023 02:03 AM
Thanks BB,
by "devices", do you mean end-users devices or right the devices in control of CP itself? In my case I mean the devices controlled by CP itself, hence routers, switches and so on.
Regards,
Gio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide