Security Basics mailing list archives

RE: Discovering network topology


From: "Ramki B" <bramkie () gmail com>
Date: Sun, 25 Feb 2007 22:26:21 +0530

I think HP Openview Network Node Manager is the answer, it even has
Layer 2 level mapping..

http://openview.hp.com/products/nnm/index.html

...Ramki 

-----Original Message-----
From: listbounce () securityfocus com 
[mailto:listbounce () securityfocus com] On Behalf Of David Gillett
Sent: Friday, February 16, 2007 6:42 AM
To: 'David Rosenhan'; 'Jeremy'; security-basics () securityfocus com
Subject: RE: Discovering network topology

  When I tried a number of tools on our network a few years 
back, all of them ran into difficulties with unnumbered 
links, trunks, secondary addresses, and redundant routing.  
And that was just layer 3 -- none of them came close on the 
layer 2 map....

David Gillett


-----Original Message-----
From: listbounce () securityfocus com
[mailto:listbounce () securityfocus com] On Behalf Of David Rosenhan
Sent: Thursday, February 15, 2007 8:07 AM
To: Jeremy; security-basics () securityfocus com
Subject: RE: Discovering network topology

Solar Winds has some nice tools for this when it comes to 
discovery...
however I have found that just about any of the tools out 
there that 
do this have one flaw or another.  You just need to try a 
few out that 
people mention here and see which one you like best.

Most of them have evaluation options.

David R

-----Original Message-----
From: listbounce () securityfocus com
[mailto:listbounce () securityfocus com]
On Behalf Of Jeremy
Sent: Thursday, February 15, 2007 1:33 AM
To: security-basics () securityfocus com
Subject: Discovering network topology

Hi list,

   I was wondering if there were special ways to discover networks

topologies / mapping networks.  Are there particular tools 
or methods 
I should be aware of ?  The few tools I tried only gave me 
approximative results.  However I think nmap + the standard 
unix tools 
can do a good part of the job.

   Moreover, what are the differences between discovering an 
organisation's network from the inside, and from the outside ?
I mean, what are the best practices to discover network
equipments, 
subnets, VPNs, etc?  I know that traceroute can be a good starting

point, but are

there some other tools and techniques I should know ?

Regards,

--
Jeremy




---------------------------------------------------------------------------
This list is sponsored by: BigFix

If your IT fails, you're out of business - or worse.  Arm your 
enterprise with BigFix, the single converged IT security and operations 
engine. BigFix enables continuous discovery, assessment, remediation, 
and enforcement for complex and distributed IT environments in real-time 
from a single console.
Think what's next. Think BigFix. 

http://ad.doubleclick.net/clk;82309979;15562032;o?http://www.bigfix.com/ITNext/
---------------------------------------------------------------------------


Current thread: