Manage Network Segments
Focus
Focus
Device Security

Manage Network Segments

Table of Contents

Manage Network Segments

Manage network segments in Device Security to properly learn devices and attributes that use overlapping IP addresses.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription for an advanced Device Security product (Enterprise, OT, or Medical)
  • Device Security X subscription
In some instances, you may need to update or delete network segments for Device Security to properly learn about devices with overlapping IP addresses. For example, if you redeploy firewalls or add firewalls to a new site, update your network segments to ensure that the traffic maps to the correct devices.
Whenever you change the firewalls assigned to a network segment, or change the network segment's site assignment, reset the network segment. If you don't reset the network segment, device attributes and behaviors learned from new traffic may be associated with different devices previously learned through the network segment.
When you no longer need a network segment, delete the network segment to ensure that attributes and behaviors get associated with the correct devices.
When you reset or delete a network segment, all devices and attributes learned through the network segment assignment are deleted from the assets inventory. Devices and attributes must be relearned from traffic through the updated network segments.

Strata Cloud Manager

Manage network segments in Device Security in Strata Cloud Manager to properly learn devices and attributes that use overlapping IP addresses.
Follow these procedures to manage network segments:

Update the Assigned Firewalls

Update the Assigned Firewalls
  1. Navigate to NetworksNetwork Segments.
  2. Click on the name of the network segment that you want to update to bring up the Edit Network Segment dialog box.
  3. In the Firewall field, add or remove firewalls.
    You can search by a firewall's serial number and name, or use the drop-down selector. The drop-down selector shows if firewalls are assigned to a network segment or not, including the network segment you're editing. If you select a firewall that is assigned to a different network segment, it's removed from its existing network segment after saving the configuration. There must be at least one firewall assigned to the network segment.
  4. Select Edit to save your changes and close the dialog box.
  5. Select the check box next to the updated network segment and Reset the network segment.
  6. Optional If you moved a firewall from one network segment to another, select the network segment that the firewall was removed from and Reset that network segment.

Update the Site Assignment from Network Segments

Update the Site Assignment from Network Segments
  1. Navigate to NetworksNetwork Segments.
  2. Click on the name of the network segment that you want to update to bring up the Edit Network Segment dialog box.
  3. In the Assigned to Site (optional) field, select or create the new site that you want to assign the network segment to.
    Select or creating a new site replaces the existing site assignment in the Assigned to Site (optional) field. A network segment can only be assigned to one site.
  4. Select Edit to save your changes and close the dialog box.
  5. Select the check box next to the updated network segment and Reset the network segment.

Update the Site Assignment from Sites

Update the Site Assignment from Sites
  1. Navigate to NetworksSites.
  2. Edit the site.
    1. In the Sites table, find the site that the network segment belongs to.
    2. Click the three vertical dots at the far right of the row and select Edit Site to bring up the Edit Site dialog box.
    3. In the Network Segment (Optional) field, add or remove network segments assigned to the site.
      If you remove a network segment from the site, the network segment is reassigned to the default site after saving the configuration.
      If you add a network segment, it is removed from its existing site after saving the configuration.
  3. Save the site configuration.
  4. Navigate to NetworksNetwork Segments.
  5. Select the check boxes next to the network segments that were removed from a site or added to a new site and Reset the network segments.

Delete or Reset Network Segments

Delete or Reset Network Segments
  1. Navigate to NetworksNetwork Segments.
  2. Select the check box next to the network segments that you want to delete or reset.
    You need to select at least one network segment to see the Delete and Reset options.
  3. Delete or Reset the network segments.

Device Security

Manage network segments in Device Security to properly learn devices and attributes that use overlapping IP addresses.
Follow these procedures to manage network segments:

Update the Assigned Firewalls

Update the Assigned Firewalls
  1. Navigate to NetworksNetworks and SitesNetwork Segments Configuration.
  2. Click on the name of the network segment that you want to update to bring up the Edit Network Segment dialog box.
  3. In the Firewall field, add or remove firewalls.
    You can search by a firewall's serial number and name, or use the drop-down selector. The drop-down selector shows if firewalls are assigned to a network segment or not, including the network segment you're editing. If you select a firewall that is assigned to a different network segment, it's removed from its existing network segment after saving the configuration. There must be at least one firewall assigned to the network segment.
  4. Select Edit to save your changes and close the dialog box.
  5. Select the check box next to the updated network segment and Reset the network segment.
  6. Optional If you moved a firewall from one network segment to another, select the network segment that the firewall was removed from and Reset that network segment.

Update the Site Assignment from Network Segments Configuration

Update the Site Assignment from Network Segments Configuration
  1. Navigate to NetworksNetworks and SitesNetwork Segments Configuration.
  2. Click on the name of the network segment that you want to update to bring up the Edit Network Segment dialog box.
  3. In the Assigned to Site (optional) field, select or create the new site that you want to assign the network segment to.
    Select or creating a new site replaces the existing site assignment in the Assigned to Site (optional) field. A network segment can only be assigned to one site.
  4. Select Edit to save your changes and close the dialog box.
  5. Select the check box next to the updated network segment and Reset the network segment.

Update the Site Assignment from Sites

Update the Site Assignment from Sites
  1. Navigate to NetworksNetworks and SitesSites.
  2. Edit the site.
    1. In the Sites table, find the site that the network segment belongs to.
    2. Click the three vertical dots at the far right of the row and select Edit Site to bring up the Edit Site dialog box.
    3. In the Network Segment (Optional) field, add or remove network segments assigned to the site.
      If you remove a network segment from the site, the network segment is reassigned to the default site after saving the configuration.
      If you add a network segment, it is removed from its existing site after saving the configuration.
  3. Save the site configuration.
  4. Navigate to NetworksNetworks and SitesNetwork Segments Configuration.
  5. Select the check boxes next to the network segments that were removed from a site or added to a new site and Reset the network segments.

Delete or Reset Network Segments

Delete or Reset Network Segments
  1. Navigate to NetworksNetworks and SitesNetwork Segments Configuration.
  2. Select the check box next to the network segments that you want to delete or reset.
    You need to select at least one network segment to see the Delete and Reset options.
  3. Delete or Reset the network segments.