| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise,
OT, or Medical)
Device Security X subscription
|
To help Device Security discover and learn about assets, next-generation
firewalls can poll devices using select protocols, without needing any additional
sensors or hardware. Depending on the network deployment, next-generation firewalls
with Device Security might not see all device traffic or enough
traffic to confidently identify some devices. Device Security uses polling to
learn about these devices that it might not be able to discover through normal network
Traffic logs. This provides greater visibility of your asset inventory and helps
discover potential vulnerabilities in the wider network.
Next-generation firewalls can poll devices using native commands within the
protocols below. Make sure your firewall can reach the devices you want to poll
using the relevant network services.
Axis Communications: TCP ports 80 and 443
BACnet: UDP port 47808
CIP: TCP port 44818, UDP port 44818
CodeSysV3: UDP port 1740
Cognex Discovery: UDP port 1069
EPM: UDP port 34964
FANUC Focas: TCP port 8193
FTP Banner: TCP port 21
IEC 61850 MMS: TCP port 102
Mitsubishi MELSEOFT TCP: TCP port 5562
Modbus: TCP port 502
Moxa: UDP port 4800
Niagara Fox: TCP port 1911
Omron FINS: UDP port 9600
Profinet I/O CM: UDP port 34964
Reverse DNS: UDP port 53
Siemens-S7: TCP port 102
Siemens-S7-Comm-Plus: TCP port 102
SNMP v2/v3: UDP port 161
UMAS Modbus: TCP port 502
UPnP: UDP port 1900
WinRM: TCP port 5985
The firewall converts the polling data to Enhanced Application logs (EAL) and sends
them to the Strata Logging Service, and then the
Strata Logging Service streams the logs to Device Security for analysis.
With advanced configuration mode, you can specify the ports for each protocol, the
timeout period, and the schedule for polling to minimize the impact of polling on
your operations.
Protocol polling is available to next-generation firewalls as part of the free
Network Discovery plugin
and does not require
Cortex XSOAR. Devices and
attributes learned through the plugin have “Device Polling” and the protocol name
as the source. Review the
Network Discovery compatibility matrix
to find the PAN-OS versions supported for each plugin release version.
Alternatively,
Device Security provides
device attributes by polling
through
Cortex XSOAR as part of the
Device Security third-party
integrations.
Strata Cloud Manager does not support plugin management. If you use
Strata Cloud Manager to access Device Security, you still need to use
Panorama or PAN-OS to manage the
Network Discovery plugin.
The following devices don't support the Network Discovery plugin:
PA-410
PA-410R
PA-410R-5G
PA-415
PA-415-5G