Network organizations
A network organization is a network-management interface that
-
enables you to define subnetworks within an industrial network by setting up ranges of IP addresses,
-
allows you to specify whether subnetworks are considered internal (OT) or external, and
-
impacts how Cyber Vision manages device licensing, flow storage, and risk assessment.
IP-address classification
In Cyber Vision, all private IP addresses are automatically classified as OT Internal. These addresses appear in the IP Address / subnet column on the Network Organization page. Public IP addresses are considered External by default, except for:
-
Broadcast IPv4: 255.255.255.255
-
IPv4 and IPv6 zero: 0.0.0.0 and 0:0:0:0:0:0:0:0
-
Loopback IPv4 and IPv6: 127.0.0.1 and ::1
-
Link Local Multicast IPv4 and IPv6: 224.0.0.0/8 and ff00::/8
If you need to treat a public IP address as OT Internal, change its network type to add an exception. This is useful for industrial sites that use public IP addresses in private networks. Marking a set of IP addresses as External will:
-
exclude their associated flows from the database,
-
remove their devices from the device license count, and
-
omit them from risk scoring.
Feature history table
|
Feature |
Release Information |
Feature Description |
|---|---|---|
|
Network based auto grouping |
Release 5.5.x |
The network based auto grouping feature streamlines device management. It automatically organizes devices based on established network definitions. Groups are created and named according to your network names. You can use this feature for easier ISE API integration and device classification. |
Define a Subnetwork
Allow precise management and monitoring of devices by defining subnetworks and specifying their characteristics.
Use this task to add a new subnetwork to your network organization. Customize IP ranges, VLANs, and network types to improve device grouping and monitoring.
Before you begin
-
Ensure you have the required IP addresses and subnets.
-
Obtain VLAN ID information if applicable.
Procedure
|
Step 1 |
From the main menu, choose Admin > Network Organization. |
|
Step 2 |
Click Add a network. |
|
Step 3 |
Enter an IP address range and its subnet in the IP address/subnet field. |
|
Step 4 |
(Optional) Enter the VLAN ID to enable overlapping networks. |
|
Step 5 |
Enter the Network name. |
|
Step 6 |
Select the Network Type (Options include OT Internal, IT Internal, or External). Select the network type to change Cyber Vision performance, flow storage, device risk scoring, and device license count. |
|
Step 7 |
Enable Use a device engine option for this network range.
|
|
Step 8 |
Click Add a network to save and apply the new subnetwork. |
You have added the subnetwork with the specified IP range, VLAN, network type, and device engine options. This enables accurate grouping and monitoring of network components.
Create network groups
Group your assests automatically according to your network definitions. These groups enable easier device management and allow you to segment your network using Cisco Identity Services Engine (ISE) integration.
Each group is named after its associated network name.
Before you begin
Ensure your network definitions are accurate and complete. From the main menu, choose Admin > Network Organization to review existing definitions.
Procedure
|
Step 1 |
From the main menu, choose Admin > Network Organization. |
||
|
Step 2 |
Click Create groups based on network.
|
||
|
Step 3 |
Select Yes or No, for the presented options:
|
||
|
Step 4 |
Click Submit. |
The system creates groups using your network definitions.
What to do next
-
From the main menu, choose Explore. Select any preset and view the groups under the GROUPS tab to see the created groups.
-
Once groups are created based on network definitions, you can synchronize them with Cisco ISE security groups. For integration details, see the “Integrate Cisco Cyber Vision with Cisco Identity Services Engine (ISE)” guide, particularly the "Chapter: Integrate Cisco Cyber Vision and Cisco Identity Services Engine (ISE) through Cisco ISE API".

Feedback