McAfee EPOCDE-AA-BA Product Guide - Page 268

Subnet status, Top 25 Subnets, Active, Missing, Passive, Contains Rogues, Covered

Page 268 highlights

21 268 Detecting Rogue Systems What are rogue systems Active Active sensors report information about their broadcast segment to the McAfee ePO server at regular intervals, over a fixed time. Both the reporting period and the active period are user-configured. A sensor becomes passive when the active period lapses, at which time the next passive sensor to report in is made active. Missing Missing sensors have not communicated with the McAfee ePO server in a user-configured time. These sensors could be on a system that has been turned off or removed from the network. Passive Passive sensors check in with the McAfee ePO server, but do not report information about detected systems. They wait for instructions from the McAfee ePO server to replace other sensors that become passive. Subnet status Subnet status is the measure of how many detected subnets on your network are covered. Coverage is determined by the ratio of covered subnets to uncovered subnets on your network. Subnet states are categorized into these groups: • Contains Rogues • Covered • Uncovered Subnets must be known by the McAfee ePO server or be seen by a sensor to fall into one of these categories. Once a subnet has been detected, you can mark it Ignored to prevent receiving further reporting about its status. Contains Rogues Subnets that contain rogue systems are listed in the Contains Rogues category to make it easier to take action on them. Covered Covered subnets have sensors installed on them that are actively reporting information about detected systems to the McAfee ePO server. The Covered subnets category also includes the systems listed in the Contains Rogues category. For example, the Covered subnets category contains subnets A, B, and C. Subnet B contains rogues, while A and C do not. All three are listed in the Covered category; only subnet B is listed in the Contains Rogues category. Uncovered Uncovered subnets don't have any active sensors on them. Subnets that are uncovered are not reporting information about detected systems to the McAfee ePO server. However, there might be managed systems on this subnet that are being reported on through other means, such as agent-server communication. Top 25 Subnets The Top 25 Subnets list provides the subnet list, by name or IP, for the 25 subnets that contain the most rogue system interfaces on your network. When a top 25 subnet is selected, the rogue system interfaces it contains are displayed in the adjacent Rogue System Interfaces by Subnet table. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Active
Active sensors report information about their broadcast segment to the McAfee ePO server at regular
intervals, over a fixed time. Both the reporting period and the active period are user-configured. A
sensor becomes passive when the active period lapses, at which time the next passive sensor to
report in is made active.
Missing
Missing sensors have not communicated with the McAfee ePO server in a user-configured time. These
sensors could be on a system that has been turned off or removed from the network.
Passive
Passive sensors check in with the McAfee ePO server, but do not report information about detected
systems. They wait for instructions from the McAfee ePO server to replace other sensors that become
passive.
Subnet status
Subnet status is the measure of how many detected subnets on your network are covered. Coverage
is determined by the ratio of covered subnets to uncovered subnets on your network. Subnet states
are categorized into these groups:
Contains Rogues
Covered
Uncovered
Subnets must be known by the McAfee ePO server or be seen by a
sensor to fall into one of these categories. Once a subnet has been
detected, you can mark it
Ignored
to prevent receiving further reporting
about its status.
Contains Rogues
Subnets that contain rogue systems are listed in the Contains Rogues category to make it easier to
take action on them.
Covered
Covered subnets have sensors installed on them that are actively reporting information about detected
systems to the McAfee ePO server. The Covered subnets category also includes the systems listed in
the Contains Rogues category. For example, the Covered subnets category contains subnets A, B, and
C. Subnet B contains rogues, while A and C do not. All three are listed in the Covered category; only
subnet B is listed in the Contains Rogues category.
Uncovered
Uncovered subnets don’t have any active sensors on them. Subnets that are uncovered are not
reporting information about detected systems to the McAfee ePO server. However, there might be
managed systems on this subnet that are being reported on through other means, such as
agent-server communication.
Top 25 Subnets
The Top 25 Subnets list provides the subnet list, by name or IP, for the 25 subnets that contain the
most rogue system interfaces on your network. When a top 25 subnet is selected, the rogue system
interfaces it contains are displayed in the adjacent Rogue System Interfaces by Subnet table.
21
Detecting Rogue Systems
What are rogue systems
268
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide