Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Anyone using NMAP in anger as part of a CPPM Service definition?

This thread has been viewed 2 times
  • 1.  Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Jun 21, 2019 05:04 AM

    Just defined a generic NMAP service in CPPM 6.8.1 and added it to our (dev) eduroam, wired dot1x wired macauth services.

     

    NMAP set up using defautls, port scan and detect operating system

     

    So, for a macauth of a Windows VM  that cppm fingerprint says is a win 10  system, nmap audit sayts its "Microsoft Windows Server 2008 SP1 or Windows Server 2008 R2"

     

    Another system that the fingerprint says is :"Windows" NMAP thinks is XP SP2, whoichI doubt 

     

    As a 1st stab at using NMAP, doesn't instill a lot of confidence 

    Pointing it at my macOS desktop ( 10.14.x) it says 

     

    Avenda:Audit:Audit-StatusAUDIT_SUCCESS
    Avenda:Audit:Device-Typeproxy server
    Avenda:Audit:Network-Appsssh, kerberos-sec, apple-xsrvr-admin,
    Avenda:Audit:Open-Ports22, 88, 625,
    Avenda:Audit:OS-InfoBlue Coat proxy server (SGOS 6.3.2.201)
    Avenda:Audit:Output-Msgs

     

    Appreciate theres gonig to be . a bit of a learning curve here , but initial glance says ... why would I use this ?

     

    A



  • 2.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    EMPLOYEE
    Posted Jun 21, 2019 05:34 AM
    The NMAP and NESSUS plugins are deprecated and should not be used.


  • 3.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Jun 21, 2019 06:01 AM

    But they are there and there's nothing to say you shouldn't use them ... and I can;t see anything in the release notes to say its depreciate ... but I might have missed it

     

    Was just trying to see why we have a whole batch of mac addresses with Device name="Windows"  and not "Windoews 7" or 8 or 10  or whatever

     

     

     



  • 4.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Nov 13, 2019 04:48 AM

    Hi!

     

    I was looking to implement client audit with nmap as a part of my wired mac-auth service.

    Is this correct, nmap is deprecated ?

     



  • 5.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Nov 13, 2019 04:51 AM

    been told it is depreciated by Tim C



  • 6.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Nov 13, 2019 10:28 AM

    Is this Aruba pushing Device Insights (is it available soon?) or are there plans to support some other methods? We have clients with static IPs that don't respond to LLDP, so wondering how to fingerprint those



  • 7.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Nov 13, 2019 10:38 AM

    No this was me trying to use what's available in CPPM but it's . depreciated.

     

    Hopefully real soon now I'[ll have a device insight box to play with for a while

     



  • 8.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    EMPLOYEE
    Posted Nov 13, 2019 12:27 PM

    NMAP is available as an endpoint context server action. Only the "Audit" feature was deprecated.

     

    Screen Shot 2019-11-13 at 12.25.36 PM.png

     



  • 9.  RE: Anyone using NMAP in anger as part of a CPPM Service definition?

    Posted Nov 19, 2019 04:47 AM

    How would I use the endpoint context action ? In an enforcement something like this ?

     

    2019-11-19_10-42.png

     

    Found this forumpost:

     

    Is this bug resolved ?