Network discovery policies overview
The network discovery policy on the Firewall Management Center controls how the system collects data on the network assets of your organization and which network segments and ports are monitored.
Discovery rule configuration
Discovery rules in the policy specify which networks and ports you monitor to collect discovery data from traffic, and the zones where you deploy the policy. Within a rule, choose whether to discover hosts, applications, and non-authoritative users. Create rules to exclude networks and zones from discovery that you do not want to monitor. Set up discovery for data from NetFlow exporters as needed. You can also restrict which protocols on your network are used for discovering user data.
By default, the network discovery policy has a single rule that discovers applications from all observed traffic without excluding any networks, zones, or ports. Host and user discovery is not enabled, nor is NetFlow exporter monitoring. The policy is deployed automatically to managed devices when you register them to the Firewall Management Center. To collect host or user data, add or modify discovery rules and deploy the policy to a device.
If you want to adjust the scope of network discovery, you can create additional discovery rules and modify or remove the default rule.
The access control policy for each managed device determines which traffic you permit and, therefore, the traffic you can monitor with network discovery. If you block certain traffic with access control, the system does not examine that traffic for host, user, or application activity. For example, when you block access to social networking applications in an access control policy, discovery data is not collected on those applications.
Enable traffic-based user detection in your discovery rules to detect non-authoritative users based on login activity in traffic across specific application protocols. Disable discovery in certain protocols across all rules if necessary. Disabling some protocols helps prevent reaching the user limit for your Firewall Management Center model and reserves user count for other protocols.
Use advanced network discovery settings to control what data is logged, how discovery data is stored, which indications of compromise (IOC) rules are active, how you map vulnerabilities for impact assessment, and how you resolve conflicting discovery data from multiple sources.
You can also add sources for host input and NetFlow exporters to monitor.



Feedback