Re: Automatically Scan for unauthorised computers



"Simon" == Simon <simon@xxxxxxxxxx> writes:

Simon> Are there any 'automatic' applications to scan for
Simon> unauthorised machines, as random manual scans are ok but
Simon> not practical.

Both Nmap and Nessus can be run by a Windows Task Scheduler job. You
can even script the Nessus plug-in update. This still doesn't give
you real-time detection, but it does automate the scanning task
itself.

If you have McAfee's ePolicy Orchestrator, you can install a Rogue
System Sensor on your network. It detects systems by listening for
ARP "who has" broadcasts (limited to the broadcast domains to which
the sensor is directly connected), which gives you real-time detection
of any active device on the network.

You might be able to approximate McAfee's rogue system detection
feature with free tools such as WinDump or Snort.

If you have the right kinds of network infrastructure, you can create
multiple VLANs, with unauthorized devices going automatically into a
quarantine network. Unfortunately, this requires the sort of network
infrastructure that is out of the reach of most small businesses
(e.g., Cisco Catalyst switches capable of being VLAN membership policy
servers).

You could also take a look at IPSEC AH group policies, although that
might be difficult to implement or to maintain.

Best wishes,
Matthew

--
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
.



Relevant Pages

  • Re: UDP over vodafone
    ... are OK for general internet browsing but not data transfer. ... This coupled with UDP, you are going to have a very unreliable system. ... Simon Harthttp://simonrhart.blogspot.com ... system switchable for UDP/TCP depending on which network it is on. ...
    (microsoft.public.pocketpc.developer)
  • Re: UDP over vodafone
    ... are OK for general internet browsing but not data transfer. ... This coupled with UDP, you are going to have a very unreliable system. ... Simon Harthttp://simonrhart.blogspot.com ... system switchable for UDP/TCP depending on which network it is on. ...
    (microsoft.public.pocketpc.developer)
  • Re: problem with configure thin node Ethernet interface
    ... >> through PSSP rather than make direct changes. ... > my internal network is private network, ... > normal class B ip ... Simon Green ...
    (AIX-L)
  • Re: UDP over vodafone
    ... I would assume that TCP should not be blocked so I will make the ... system switchable for UDP/TCP depending on which network it is on. ... It's quite possible that the incoming UDP packets are ... Simon Harthttp://simonrhart.blogspot.com ...
    (microsoft.public.pocketpc.developer)
  • RE: Automated network drawings based on database records
    ... I have a visio solution that can automate network drawings based upon ... The project also links the database to the actual ...
    (microsoft.public.visio.general)

Loading