vA Discovery policy applies to only the group where you define it.

vThe remaining policies are inheritable. A subgroup inherits a policy from the first group higher than itself in the group structure that has a defined policy.

In the SiteProtector Console, you select a group in the left pane and the applicable policies are displayed in the right pane in a Policy tab.

Discovery policy

Use the Discovery policy on the SiteProtector Console to define parameters used to perform discovery on a portion of a network.

In a discovery task, a range of IP addresses is scanned to locate active network interfaces, and the type of device associated with each active network interface is determined through OS identification.

Scope

The Discovery policy applies to background discovery scans. An ad hoc scan reads this policy and uses its settings to initialize the ad hoc discovery scan. You can change the settings in the ad hoc scan without changing the background policy.

Policy contents

Each Discovery policy defines the following information:

vA range of IP addresses to be scanned (specified as a combination of dotted-decimal IP addresses and address ranges, and subnetworks specified in CIDR notation).

vWhether to ping each IP address before scanning to exclude unreachable hosts from the scan.

vWhether newly discovered assets should be added to the associated group.

vWhether previously known assets that do not already belong to the associated group should be added to the group.

46Enterprise Scanner: User Guide

Page 54
Image 54
IBM Partner Pavilion 2.3 manual Discovery policy, Scope, Policy contents