Zum Inhalt springen

Scanner

Every other discovery source waits for something to come to it: the DHCP Probe waits for a request, the Web Probe asks a system you own, and SNMP asks the switch. The Scanner is present on the wire itself. It hears what devices announce and, where you allow it, asks them what they are. It covers what the other sources miss: the printer, the camera, the server with a static address, and the laptop that has not asked for a lease since Monday.

Presence only works from inside the broadcast domain, so a scanner is always a site collector and never the core. The Scanner is found under NAC → Discovery Sources → Scanner, and what it finds is in the journal under NAC Logs → Scanner.

One zone, four methods. Listening hears the devices that announce themselves. Discover finds the silent laptop’s address, Identify gets it to name itself, and Deep reads the server’s software. The excluded PLC is heard, and receives no packets. The methods are shown one after another here, but a zone uses any combination you tick.
TermWhat it means
ScannerA connected collector, which reports every interface of its host. Every standalone collector is a scanner. Nothing is switched on at install time.
InterfaceA physical port, a VLAN sub-interface or virtual plumbing, as the collector’s kernel reports it. Every interface can listen. An interface with an IPv4 address can also scan.
ZoneOne rule: a scanner, one or more of its interfaces, and the methods to use there. It has a name that is unique across the installation. A zone with an active method is the consent to send.
MethodListen, Discover, Identify or Deep. These are four independent choices, not steps on a ladder.
FindingOne device on one wire, as one scanner knows it: one row per scanner, interface and MAC, updated on every sighting. It records current state, not a stream of events.
ExclusionA device, or an endpoint group, marked not to be scanned actively. The device can still be heard, but no active method sends it anything.

A connected collector describes every interface of its host: the name, what the kernel says it is (Physical, VLAN or Virtual), whether the link is up, its MAC, its first IPv4 address, and for a sub-interface the VLAN tag and the parent it runs on. It also reports whether nmap is installed and which version.

  • The list of interfaces is read once, when the collector starts. A container host creates and removes veth pairs all day, and a list that followed them would change on your screen constantly. An interface you add appears after you restart the collector. Link state and addresses are read again on every report.
  • An interface that disappears is shown as down until the collector restarts. Running netplan apply recreates VLAN sub-interfaces, and this rule keeps that from wiping the zones built on them. After a restart, an interface that is really gone is removed from every zone that used it, a zone left with no interface is deleted, and each change is written to the audit log.
  • The VLANs seen on a trunk are reported too. The collector samples the 802.1Q tags that arrive on each physical interface, and the scanner’s card lists them as VLANs in traffic. A VLAN that already has a sub-interface on this machine is shown muted. A VLAN that has none is highlighted, and Sub-interfaces for N VLAN(s)… opens a ready netplan file for exactly those VLANs (see Scanning a trunk). The list covers recent traffic only: a VLAN stays on it for an hour after it was last heard. A VLAN missing from the list does not prove the trunk doesn’t carry it.

The one thing you state per interface is its VLAN (Scanners tab → the scanner). A sub-interface’s tag is filled in automatically. An access port’s frames carry no tag, so only the person who patched the port knows its VLAN. Type it in, and it labels everything found on that wire. Every change is audited.

On the Zones tab, Add zone asks for a Zone name, a Scanner and its Interfaces, and What to do: the methods. Two rules follow from the machine rather than from the form:

  • An interface with no IPv4 address can only listen. Nothing can be sent from it, so the other methods are shown disabled. That is how you learn that the missing address is the reason. A trunk’s parent usually has no address: listen on it, and scan from its VLAN sub-interfaces.
  • Deep needs nmap on that scanner. Without it, the method stays visible and disabled.

Two zones on one scanner may not name the same interface. Zone is active pauses a zone without losing its settings. A zone stays on the scanner it was created with. To move it, create it on the other scanner and remove the old one.

Saving a zone is the permission to send packets, and it is audited: the audit log records who created, changed or removed the zone and with which methods. A saved change reaches the site within seconds, and stopping a zone stops its socket there. The collector listens only on interfaces a zone names. Capturing traffic on a wire nobody chose would be wrong even though nothing is sent.

A zone performs every method you tick, on every interface in it. The methods are independent. Listen + Deep, for example, means: hear who announces themselves, then look closely at exactly those hosts, without ever sweeping the subnet.

MethodWhat goes on the wireWhat it learns
ListenNothing. A raw socket reads the frames that arrive on the interface.IP and MAC of every host that speaks ARP, which is nearly all of them. Names, models and service types from mDNS. The SERVER line and model from SSDP/UPnP announcements. The Windows name and workgroup from NetBIOS. The switch and port a host is attached to, and a device’s own self-description, from LLDP and CDP.
DiscoverFor each address in the interface’s subnet, one empty UDP datagram to the discard port (9), paced in small batches. This makes the collector’s kernel resolve the address over ARP. The replies are read by the listening socket. Then one reverse DNS lookup per host, against the collector’s own resolvers.Every host that is switched on, including ones that never speak, with MAC, manufacturer (from the OUI database) and a DNS name where the site keeps records.
IdentifyPer host found: TCP connections to a short port list (by default 22, 80, 135, 443, 445, 3389, 8080, 8443, 515, 9100, 161), opened and closed cleanly. Reads of the greeting on those ports. Three unicast questions: a NetBIOS node-status query (UDP 137), a unicast mDNS / DNS-SD query (UDP 5353) and an SSDP M-SEARCH (UDP 1900).Which common ports are open. The SSH banner, the HTTP Server header and the names in a TLS certificate. The names a quiet laptop or phone gives when asked directly, filed exactly as if it had announced them.
Deepnmap, run only against hosts already found and never as a sweep: -sV -O --top-ports 200 -T3, with version intensity from Settings (default 5). No scripting engine and no vulnerability probes. At most 5 minutes per host.The product and version behind each open port, and an OS guess with nmap’s own confidence.

A few details matter in practice:

  • Discover also listens. A leg with Discover opens the listening socket, because that is where the sweep’s replies arrive, so a Discover zone also records what the leg hears.
  • Identify and Deep aim at hosts the scanner has already met on that interface, whether by listening or by Discover. Ticked alone, on a quiet leg, they have little to work on.
  • A device seen for the first time is scanned at once. Otherwise it waits out the re-scan interval (one hour by default), and the wait is remembered on disk, so a restart does not rescan the whole estate. A device that appears while a long pass is running is picked up on the next tick, without waiting for the pass to finish.
  • The load is limited per device. Identify works on up to 32 hosts at a time with 1.5-second timeouts. Deep runs 4 to 8 nmap processes, depending on the collector’s CPU. Discover refuses a subnet larger than a /16.
  • An nmap that may not fingerprint (missing cap_net_raw) still runs the service scan without -O, and the transcript says why the OS guess is absent.

Some equipment does not survive being probed: old printers, PLCs, medical devices. Mark it on the endpoint (Do not scan this device actively) or on an endpoint group (Do not scan anything in this group actively). If either the device or any group it belongs to says no, the no wins.

  • An excluded device’s address is left out of the Discover sweep, and Identify and Deep never target it, including when someone presses Scan this zone now.
  • Listening continues, because listening puts nothing on the wire. The device still appears in the journal with what it announced.
  • A group exclusion is a policy, not a note about one machine. It applies to equipment nobody has met yet as soon as classification places it in the group.
  • An exclusion reaches the site within seconds, just like a zone change.
  • The one deliberate exception is a person scanning that single device on demand from the journal. That is allowed because someone asked. The transcript records this device is marked as not to be scanned — running anyway, because you asked, and the request is audited.

Exclusion is by MAC, and a site is told only about the excluded devices it has already met. A device a scanner has never seen cannot be recognised as excluded yet, so on the very first Discover pass of a new zone it receives the single sweep datagram like every other address. Keep equipment that must never receive a packet in a zone that only listens.

Hearing a device makes sure it has an endpoint. A MAC no endpoint has is created with status unknown, which is the honest status: the device was heard and nothing more. Surfacing such devices is the whole point of the journal. Each sighting also marks the device for Device Profiling, so its profile follows within seconds.

The scanner supplies evidence only and never states an answer. The rules decide what a banner means. The signals it gives the profiler are: open ports, the banners on them, the nmap OS guess and service lines, UPnP SERVER lines, mDNS service types, names and model identifiers, the NetBIOS workgroup, and LLDP/CDP self-descriptions. For each method, the newest reading is used. A port list from a month ago on another wire is not treated as a second witness. The shipped rules can name a Windows machine from ports 135 and 445 and its banners, with no DHCP relay, portal or directory involved. See Profiling rules for writing your own.

Zones: every zone with its Scanner, Interfaces, Methods, Enabled state and Activity: Idle, Queued, or the method and interface in progress with a count and a percentage. A zone whose interface is down or has lost its address is flagged (Down, Address lost). With the scan permission, Scan this zone now re-runs the zone’s active methods over every host its scanner knows. It can be pressed at most once a minute per zone, and every request is audited. What does each method do? in the zone drawer explains each method’s packets, findings, cost and requirements.

Scanners: every connected collector with its Status, nmap (installed / not installed), Zones and Interfaces, and a note when one is busy (identify running). The scanner’s card lists its interfaces with their kind, Address, what the interface Can do (Listen and scan or Listen only), the zones that use it and its VLAN. Virtual interfaces are folded away by default.

Settings: four values that apply to every scanner. They reach the sites with the next report, and nothing needs restarting.

The Scanner Settings tab: Re-scan a device after 3600 seconds, Forget a wire after 30 days, Send findings every 5 seconds, the Identify port list, and the deep scan intensity slider at 5

SettingDefaultRangeMeaning
Re-scan a device after (seconds)360060 – 604800How long before an already-scanned device is scanned again by the active methods. A new device is scanned at once, whatever this says.
Send findings every (seconds)51 – 300How long a site collects sightings before sending a batch. Sightings are de-duplicated within the batch.
Forget a wire after (days)300 = neverA finding whose device has not been seen for this long is deleted. This exists because a device that moves VLAN leaves its old row behind.
Ports the Identify method checks22, 80, 135, 443, 445, 3389, 8080, 8443, 515, 9100, 161up to 32 portsKeep it short: Identify should take about a second per host. Add the ports your estate cares about, for example 104 for DICOM or 102 and 44818 for industrial controllers.
How hard a deep scan tries52 – 7nmap’s --version-intensity. It is what decides how long Deep takes: against one slow firewall, 2 took 41 seconds and 7 took 150.

Viewing needs the Network Scanner view permission. Creating and changing zones needs Manage zones. Pressing a scan button needs Run a scan, which is kept separate on purpose, because a person pressing it puts packets on the network right away.

The journal answers “what is on that wire, and when did I last see it”. There is one row per device, and paging counts devices:

ColumnWhat it shows
MAC addressWith a link to the device.
AuthorisationUnknown: no endpoint, or an endpoint nothing has vouched for. Known: NAC knows it and it is not blocked. Blocked: explicitly forbidden, and on the wire anyway. This is worked out when you view it, so blocking a device changes its row at once.
IP address, VLAN, Last seenFrom the newest sighting.

Filter by Authorisation and Zone, or search by MAC, address or scanner. Arriving from a zone narrows the journal to that zone’s wires.

Opening a device shows:

  • Where it was seen: every scanner and interface that heard it. Each scanner is a separate witness with its own row, seen by 2 scanners, and the VLAN it was heard in. A frame heard tagged on a port is labelled Heard tagged on this port — it carries more than one VLAN, and an untagged one is labelled on this port’s own VLAN. Opened from a zone, the drawer notes how many other places the device was heard, outside this zone.
  • What the scanner learned, method by method (Found by), in plain words (the Windows name it registered, the Cisco neighbour it is plugged into).
  • A method that ran and found nothing says so. For example: Ran — nmap found nothing open, Ran — none of the ports it knocks on answered, and the device did not answer when asked its name, or Ran — the site’s DNS has no name for this address. If the latest run found nothing, the drawer says so and still shows what the run before it found, because a device that was off during a scan has not changed. A method that has never run on the device is marked never run.
  • Scan buttons per method (with Run a scan): Identify again, Deep again, and so on. The request is queued, the collector checks for it every few seconds, and you can watch the full transcript: what was sent, which resolvers were asked, and what came back. The same device can be scanned at most once every 5 seconds, and a request not answered within 10 minutes stops being shown as in progress.

Taranac does not ship nmap. Commercial redistribution requires a licence from its authors that Taranac does not hold, so the collector image never contains it. Instead, the collector host builds its own image from its own package mirrors:

Terminal window
./collector-join.sh --core <url> --enrollment-token <token> --with-nmap

With --with-nmap, or by answering y when the script asks install nmap on this scanner? in a terminal, collector-join.sh:

  1. builds a derived image …-nmap from Dockerfile.nmap, which ships beside the script, on top of the collector image the install uses. nmap comes from the host’s own distribution mirrors, and the binary is given cap_net_raw and cap_net_bind_service, the capabilities the OS fingerprint needs.
  2. checks that nmap actually runs in that image as the unprivileged collector user (nmap --version), and stops with an explanation if it does not. A successful build alone does not prove that nmap runs.
  3. records the image as COLLECTOR_IMAGE in .env.collector, so later updates keep using it.

To do it by hand, build the image with docker build --build-arg BASE_IMAGE=<collector image> -t <image>-nmap -f Dockerfile.nmap . and set COLLECTOR_IMAGE in .env.collector. The collector finds nmap on PATH and offers Deep on its next report. Without nmap, a scanner offers Listen, Discover and Identify.

The collector’s compose file uses the host’s network by default (COLLECTOR_NETWORK_MODE=host). This is what lets the scanner see the host’s real interfaces, VLAN sub-interfaces and trunk tags, and it is also what makes the collector reachable as a DHCP listening point. A collector has no inbound service and publishes no port, so Docker’s network isolation adds little.

COLLECTOR_NETWORK_MODE=bridge gives the container its own isolated network, at a cost. Inside a bridge network the container sees only its own Docker interface, not the site’s wires, so there is nothing useful to build a zone on, and the DHCP listening point cannot be reached.

A trunk can be used in three ways, and they can be mixed on one machine:

The trunk interface…What you get
as it is, with no addressListen only, but it hears every VLAN on the trunk, and each finding is labelled with the tag of the frame it arrived in.
plus a VLAN sub-interface with an address, per VLANActive scanning of that VLAN, from its sub-interface.
itself carrying an address in the native VLANScans the native VLAN and still hears and labels the tagged VLANs.

Sub-interfaces are needed only for the VLANs you want to scan actively. On the scanner’s card, Sub-interfaces for N VLAN(s)… generates a netplan file for the VLANs it has seen but cannot scan. Give each sub-interface a free static address from its VLAN, outside any DHCP range, with no gateway and no DHCP. A second default route would take the collector’s path to the core away from its management interface. Apply the file with sudo netplan apply, then restart the collector (docker restart taranac-collector) so it reads the new interfaces.

Listening is safe everywhere. Everything else is a decision about a particular network, and the zone is where you make it.

NetworkSuggested methodsWhy
Any segment you want visibility intoListenSends nothing. Nearly every host speaks ARP, and many announce far more.
User and office VLANsListen + Discover + IdentifyFinds silent laptops and phones and gets them to name themselves, at a few dozen packets per host.
Server and infrastructure VLANs you own+ DeepService versions and an OS guess where software inventory matters. Tell the server team, because Deep is noisy in IDS logs.
Printer, camera and IoT VLANsListen + Identify, Deep only after a trialIdentify’s port list covers printing (515, 9100) and web interfaces. Some embedded devices stall under a version scan.
Industrial (OT), medical, building controlListen only, plus exclusionsSome controllers are known to stall under a version scan, and not every device tolerates even a connection attempt. Exclude the fragile groups, and use a listen-only zone for anything that must never receive a packet.
A guest or untrusted VLANListen, optionally DiscoverYou learn what is there without interacting with devices you do not own.
Someone else’s network (a tenant, a partner)None without their consentA zone with active methods is your organisation’s consent to send, and the audit log records who gave it.

Before enabling active methods on a segment for the first time, tell the people who watch its IDS. Discover sends about 250 datagrams for a /24 over a few seconds, Identify a few dozen packets per host, and Deep thousands.

ItemValue
MenusNAC → Discovery Sources → Scanner (Zones, Scanners, Settings); NAC Logs → Scanner
Runs onStandalone collectors only
Listen protocolsARP, mDNS, SSDP, NetBIOS, LLDP, CDP (receive only)
DiscoverEmpty UDP datagram to port 9 per address; reverse DNS; subnets up to /16
IdentifyTCP connect to the configured ports (max 32), banners, TLS names; unicast NetBIOS (UDP 137), mDNS (UDP 5353), SSDP (UDP 1900)
Deepnmap --privileged -sV -O --top-ports 200 -T3 --version-intensity <2–7> (without -O where not permitted); 5 minutes per host
On-demand limits5 seconds per device; 60 seconds per zone; in progress for at most 10 minutes
PermissionsNetwork Scanner: View scanners, Manage zones, Run a scan
RetentionFindings: 30 days since last seen (job Scanner Finding Retention)
Collector networkingCOLLECTOR_NETWORK_MODE = host (default) or bridge
nmapNot shipped; collector-join.sh --with-nmap or Dockerfile.nmap