ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

How to scan your network for free

Michael Mullins

Published: 02 Feb 2004 12:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Are you absolutely sure you know all the protocols and ports that are open on your network? If you're not the only person with the rights and permissions necessary to add devices to your network, you'll never know what's really "live and on the wire" -- unless you listen to your network. By periodically scanning your network, you'll be able to maintain a good view of what devices are connected to it and to determine whether those devices are communicating properly and using the allowed ports and protocols.

Start scanning
Depending upon the OS on your administrator's workstation, you could start by using scanning tools such as fping or SuperScan, which allow you to quickly scan a range of IP addresses to detect live network connections. This is one way to determine if someone is adding devices to the network without your knowledge and/or approval.

However, some devices (e.g., wireless devices) will need a different tool for discovery. If you're looking for rogue wireless access points (WAPs), you can use tools such as Kismet or NetStumbler. Finding an unauthorised WAP behind your security perimeter is bad news, but not finding one that's tapped into your network is even worse.

Take action
Ideally, you shouldn't find any surprises in your network scan results. If you do, though, take these steps.

Rogue WAPs
Immediately block the IP address of the WAP device at the switch where it's connected. This should provide you with enough time to find the physical device while the user is trying to discover what happened to his or her wireless network connection.

Non-wireless devices
If you find unknown non-wireless devices -- such as printers, departmental FTP/Web servers, etc. -- conduct an in-depth scan and determine exactly what the device's function is. Block the device from the network until you can physically locate it and disconnect it.

For a more thorough examination of the rogue device, you can use Ettercap or Winfingerprint. Both utilities do an excellent job of decoding the type of OS that's running on a remote device, which should help you discover the device's original purpose. These utilities also show what services are running and what ports are listening for connections.

Final thoughts
As administrators, it's our job to ensure that only authorised and secured devices operate on the network. Besides the obvious security reasons, there are performance gains to turning off unnecessary network protocols. Turning off unnecessary protocols helps reduce network chatter and increases bandwidth utilisation.

I've mentioned a lot of network tools in this article, all of which are free. If you use these tools to listen to your network and map every IP address, you might be surprised by what you find.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
57 out of 94 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Embedded Engineer - DERBY - Device Drivers

An Embedded Software Engineer is needed in the East Midlands to join a huge multi-national organisation that specialises in innovative product design ...

Lead Platform Designer : Thames Valley : Contract

Knowledge within a design capacity with the following technologies would be of interest: o UNIX, Perl and SQL o TCP/IP and IP-based protocols o ...

Graduate Opportunites

Youll discover we are diversely talented, closely-knit teams, with a truly collaborative working culture. Opportunities that mean they can feel ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment