Previous Topic: Network ProfilesNext Topic: Enable Network Profiles


Create Network Profiles

You can create Network Profiles to manage network discovery operations.

Follow these steps:

  1. Click the Management link, then the Network tab.

    The Network tab page appears.

  2. Click the Network Profile link.

    The Network Profiles page appears.

  3. Select Create Network Profile from the Table Actions drop-down list.

    The Profiles page of the Network Profiles wizard appears.

  4. Enter the following information in the corresponding field, then click Next:
    Name

    Defines the name of the Network Profile.

    Description

    Describes the function of the profile.

    Network Discovery Gateway

    Defines the computer that performs the Network Discovery. The drop-down list displays all computers where NDG is installed.

    Network Scan Policy

    Defines which Network Scan Policy to use. Network Scan Policies define which discovery engine and which methodology the network discovery uses. The Network Scan Policy drop-down list contains entries from the table on the Network Scan Policy tab page. You can view a description of each policy on the tab page. You can view a description of the predefined policies that CA Configuration Automation installs in View Network Scan Policies.

    The main types of Network Scan Policies are:

    • ARP Cache Scan
    • DNS Scan
    • Cloud Service Scan
    • IPv6 Local Link Scan
    • Netflow Analysis
    • Packet Analysis
    • Pingsweep Scan
    • TCP Connect Scan

    Each policy type also has scan options (for example, Pingsweep Scan with Softagent or Pingsweep Scan with Softagent, but without Server Relationships). The fields that are displayed in Step 5 vary depending on which Network Scan Policy you select.

    Credential Vault

    Defines which Credential Vault Profile to use for network access. The Credential Vault drop-down list contains the profiles that you created. The drop-down list also contains a Use Default option that assigns the default Credential Vault Profile for the Network Profile you are creating.

    Scan Type

    Specifies whether the scan processes the scan request with IPv4 or IPv6. For example, if you only select the IPv4 check box, the product uses IPv4 to process the scan. The Discovery operation that uses this profile discovers both IPv4 and IPv6 networks.
    Default: Both

    Network Realm

    Defines the realm in environments that have multiple, private networks. These private networks are independent of each other, which can cause conflicts when you try to discover and manage servers with duplicate IP addresses. To identify private networks uniquely, assign each a Network Realm string.

    Note: You can customize the Server table on the Servers tab to display the Network Realm column (as described in Filter Table Views). The column displays the name of the Network Realm that is associated with each server. To modify the realm, click the link in the Server Name column to display the Server Details page, and then select a Network Realm or enter a new name.

    Set Server State as Managed

    Specifies whether discovered servers are automatically set to the Managed state when they are added to the Servers table.

    Access Profile

    Defines which Access Profile to use to access the discovered servers. When you select an Access Profile, the Test Server for the CA Configuration Automation Agent field becomes active.

    Test Server for CA Configuration Automation Agent

    Specifies whether to verify that a CA Configuration Automation Agent is installed on the discovered server. An Access Profile is required for the test operation to be performed.

    Management Profile

    Defines which Management Profile is assigned to the discovered servers.

    The Inclusions page opens unless you selected one of the IPv6 Local Link Scan policies, in which case the Schedule page opens. If the Schedule page opens, continue with Step 8.

  5. Complete the following fields if they appear on the Inclusions page (not all options appear for all Network Scan Policies):
    Target Host Names - Add New Host Name

    Defines one or more target servers for the discovery. Enter the server name in the Add New Host Name field, then click the right arrow (>). The server appears in the Selected Host Names column.

    Define at least one Target Host Name or Target IP Address for a Network Scan Policy that displays these fields.

    Target Host Names - Add From File...

    Defines the .csv file from which to import target servers.

    Follow these steps:

    1. Click Add From File... in the Target Home Names column.
    2. On the Add Servers From File dialog, click Choose File, browse to the CSV file location, and then click Open.
    3. Click the File Delimiter drop-down list and then select either Comma or Tab.
    4. Click OK.

    The product adds the servers that are listed in the file to the Selected Host Names field. Click the left arrow (<) to remove unwanted servers.

    Target IP Addresses - Add New IP Address

    Defines one or more target IP addresses for the discovery. Enter the IP address in the Add New IP Address field, then click the right-facing arrow. The server appears in the Selected IP Addresses column.

    Target IP Addresses - Add From File...

    Defines the .csv file from which to import the target IP addresses.

    Note: The IP address import supports the use of an asterisk (*) as a wild card and subnet reference characters. For example:10.10.10.* or 10.10.10.0/24

    Follow these steps:

    1. Click Add From File... in the Target IP Addresses column.
    2. On the Add IP Addresses From File dialog, click Choose File, browse to the CSV file location, and then click Open.
    3. Click the File Delimiter drop-down list then select either Comma or Tab.
    4. Click OK.

    The product adds the IP addresses that are listed in the file to the Selected IP Addresses field. Click the left arrow (<) to remove unwanted IP Addresses.

    Target TCP Ports - Add New TCP Ports

    Defines the TCP ports that are monitored during a discovery. The product discovers only the network traffic that uses these ports.

    Enter the port number in the Add New TCP Port field, then click the right-facing arrow. The port number appears in the Selected Ports column. During the TCP Connect scan, only the selected ports are probed during the discovery scan to detect the open ports.

    Note: If you define the inclusion or exclusion ports for the TCP Connect scan, the default connection timeout value is 1 millisecond to detect the open ports.

    For an NDG server, add the following registry parameter to configure the connection timeout to a higher value:

    • (32-bit machines) HKEY_LOCAL_MACHINE\SOFTWARE\ ComputerAssociates\Network Discovery Gateway\TcpConnectTimeout
    • (64-bit Machine) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ComputerAssociates\Network Discovery Gateway\TcpConnectTimeout

    Note: To detect the open ports accurately, set the timeout value that is based on the ping response time between the NDG server and target machine.

    IPv6 Subnet

    Specifies an IPv6 subnet hierarchy by clicking the up and down arrows in the following fields:

    Global Routing Prefix Length

    Defines the number of bits that precede the subnetID in the IPv6 address. If the global routing prefix length is less than 64, define at least one subnet level in the remaining fields.

    Default: 48

    Bits Per Level

    Associates the bits in the subnetID with subnet levels in an IPv6 subnet hierarchy.

    Note: The bits are left justified. The first subnet level comprises the leftmost n bits of the subnetID. A corresponding filter in scan policies lets you use these bits to filter scan requests.

    Lower Bound

    Identifies the lower bound of the range of values to be included in the subnet hierarchy.

    Upper Bound

    Identifies the upper bound of the range of values to be included in the subnet hierarchy. This value cannot be larger than the maximum number that the number of bits that are reserved for this level can represent.

    Add Level

    Defines another IPv6 subnet level. Click Add Level and then enter the Bits Per Level, Lower Bound, and Upper Bound for this level. You can use the bits higher than the number specified in the Global Routing Prefix Length field to define the subnet. If it is set to the default (48), you can assign the next 16 bits to subnets.

    Remove Level

    Removes the first (top) level of subnet filtering.

    Note: When NDG discovers relationships, the product collects a relationship if either server in the relationship is targeted using the specified inclusion criteria. The product creates a corresponding server entry in the CA Configuration Automation Database if the selection criteria does not include the second server, but it does not exercise the Soft Agent options. Instead, the product performs only an entity-level discovery for the second host (that is, it gathers the host name, IP, and operating system classification).

  6. On the Exclusion page, repeat Step 5, but specify the host servers, IP addresses, and port number to exclude from the discovery.

    Note: When NDG discovers relationships, the product does not collect the relationship if either server in the relationship is targeted using the specified exclusion criteria.

  7. Click Next.
  8. On the Schedule page, select one of the following values from the Frequency drop-down list:
    Not Scheduled

    Specifies that the profile does not run automatically. You can run the profile manually or you can schedule it later.

    Once

    Specifies that the profile runs automatically one time. Specify when to run the profile in the Time field if you select this option.

    Minutes

    Specifies that the profile runs at specific intervals (in minutes). Define the following properties if you select this option:

    • Start Time: Set the time at which to start running the profile.
    • Begin Date: Set the first date on which to run the profile.
    • End Date: Set the last date on which to run the profile.
    • Recur every # minutes: Set the interval at which to run the profile.

    For example, to run the profile every 10 minutes starting at 11:00 p.m., specify a Start Time of 11:00:00PM and specify Recur every 10 minutes. The profile runs at 11:00 p.m., 11:10 p.m., 11:20 p.m., 11:30 p.m., and so on. The next profile starts when the current profile completes.

    Hourly

    Specifies that the profile runs at specific intervals (in hours). Define the following properties if you select this option:

    • Start Time: Set the time at which to start running the profile.
    • Begin Date: Set the first date on which to run the profile.
    • End Date: Set the last date on which to run the profile.
    • Recur every # hours: Set the interval at which to run the profile.

    For example, to run the profile every four hours starting at 11:00 p.m., specify a Start Time of 11:00:00PM and specify Recur every 4 hours. The profile runs at 11:00 p.m., 3:00 a.m., 7:00 a.m., 11:00 a.m., 3:00 p.m., and so on. The next profile starts when the current profile completes.

    Note: If the Start Time has already passed in the current day, the profile runs immediately and then the product resumes the specified recurring schedule.

    Daily

    Specifies that the profile runs at specific intervals (in days). Define the following properties if you select this option:

    • Start Time: Set the time at which to start running the profile.
    • Begin Date: Set the first date on which to run the profile.
    • End Date: Set the last date on which to run the profile.
    • Recur every # days: Set the interval at which to run the profile.
    Weekly

    Specifies that the profile runs at specific intervals (in weeks). Define the following properties if you select this option:

    • Start Time: Set the time at which to start running the profile.
    • Begin Date: Set the first date on which to run the profile.
    • End Date: Set the last date on which to run the profile.
    • Days: Set the days on which the profile runs every week.
    Monthly

    Specifies that the profile runs at specific intervals (in months). Define the following properties if you select this option:

    • Start Time: Set the time at which to start running the profile.
    • Begin Date: Set the first date on which to run the profile.
    • End Date: Set the last date on which to run the profile.
    • Recur every # months: Set the interval at which to run the profile on the specified days.
  9. Define the notification that is used when the profile runs in the following fields:
    Notification Profile

    Defines which notification profile to use when discovery with this profile runs as scheduled. For information about creating notification profiles, see Create Notification Profiles.

    Subject

    Defines the subject line of the email that the selected notification profile sends.

  10. Click Finish.

    The product creates, enables, and adds the profile to the Network Profile table.