Skip to content

Network inventory and change control

The appliance regularly recounts what lives in your network and reports when the picture changes: a new host appeared, a new port opened, a device went missing.

ports in a full TCP scan
65,535ports in a full TCP scan
scan profiles
8scan profiles
arbitrary task schedules
CRONarbitrary task schedules
Network monitor · Scan result
Результат сканирования сети модулем «Монитор сети»: обнаруженные хосты, MAC-адреса, открытые порты, сервисы и версии программного обеспечения
For every discovered node: address, domain name, MAC, open ports, protocols and service versions. The example shows MikroTik routers, Kyocera printers and servers running OpenSSH, nginx and PostgreSQL.

How it works

An administrator sets an address range and a scan profile, then a schedule: every minute, hourly, daily, weekly or through an arbitrary CRON expression. After that the appliance works on its own.

The core idea of the module is the baseline. Any scan result can be declared a reference, and every later check will be compared against it. If no baseline is set, the result is compared against the previous scan. One baseline belongs to one task.

The outcome is not a list of addresses but an answer to the question of what changed since yesterday. This is exactly how you find devices connected without approval, ports accidentally exposed outside and services someone spun up in the middle of a working day.

Which changes are recorded

Module events
  • New host discovered
  • Port change
  • Host disconnected
  • New port
  • Port closed
  • Port state change
What is collected for every node
  • IP address and domain name
  • MAC address and username on the device
  • Port number and protocol
  • Port state: open, closed, filtered
  • Service name and version
Network monitor · Events
События модуля «Монитор сети»: обнаружен новый хост, открылся новый порт, порт закрыт, хост отключён
Deviations from the baseline: new host discovered, port change, host disconnected. Each event states exactly which port opened or closed.

Scan profiles

Normal scan

The thousand most common ports, host discovery via ping. A sensible default.

Quick scan and quick scan plus

The hundred most common TCP ports. The plus variant also detects the operating system and service versions.

Intensive scan

Detection of the operating system type, services and their versions. There is a variant with UDP ports, a variant covering all TCP ports from 1 to 65535 and a no ping variant for hosts that block it.

Slow comprehensive scan

A thorough check with the widest set of parameters. For a planned audit rather than a daily schedule.

We will prepare a quote for your network

Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.

  • We reply within one business day
  • We design the connection scheme for your topology
  • We show the interface on a live demo unit

Request a quote

Leave a phone number or an email so we can reply.

By submitting this form you agree to our privacy policy.