- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
3 hours ago
I am sure you all have heard the story of the sand, pebbles, and rocks before. It is all about the order you add them, so everything fits in a jar. Let’s put this in Centrix terms.
- If you add the “sand or span” first, then you increase the number of duplicate devices that may not get merged later down the road.
- If you add the integrations with strong identifiers first, then by the time the “sand or span” is added everything merges correctly and the system runs in the most efficient manner.
- Why is this? Placement of Armis collectors determines the quality of the span. If the span is mostly L3 or IP only traffic, then strong identifiers are not created. For Centrix to create a “strong” device or what we call “Full Visibility” we need a valid MAC address and IP address pair. If the span is getting good L2 & L3 traffic, then we have better quality data.
- There is a better process to always guarantee good quality data upfront. It is all about deployment order.
- You want the span as close to the assets as possible. Distribution switches are ideal for span location as they will see traffic coming from access switches plus see traffic going to the core.
Let’s talk about how we can improve deployments.
- Device ARP = Rocks
- Device MAC = Pebbles
- SPAN = Sand
- Data enrichment integrations can be added later to add more data to Centrix.
What integrations provide the strong ARP identity data (in preferred order):
- Network Mapper
- WLC
- Aruba Central
- Aruba Instant
- Aruba WLC
- Cambium cnMaestro
- Cisco Catalyst
- Cisco WLC
- Cisco DNA Center
- Cisco Meraki
- ExtremeWireless WING
- HP WLC
- Juniper MIST
What integrations provide the strong MAC identity data (in preferred order):
- Endpoint Agents
- Absolute
- Carbon Black Defense
- Check Point Harmony
- Cisco Secure Endpoint
- Cortex XDR
- Crowdstrike
- CylancePROTECT
- FireEye Endpoint Protection
- Ivanti Endpoint Manager
- Malwarebytes
- McAfee ePO
- Microsoft Defender
- SentinelOne
- Symantec Endpoint Protection
- Sophos Endpoint Protection
- DHCP
- BlueCat DDI
- Infoblox DDI
- Infoblox DDI Syslog
- Microsoft DHCP
- Efficient SOLIDserver DDI
- Cloud Integrations
- AWS
- Microsoft Azure
- Google Cloud
- Virtual System Management
- Microsoft Hyper-V
- vSphere vCenter
- Nutanix Prism
- NAC/Firewall
- Aruba Clearpass
- Check Point IoT Controller
- Cisco ASA
- Cisco ISE
- Fortinet Fortigate
- Palo Alto Network Enrichment
- Palo Alto GlobalProtect
- Zscaler
Once the device IDs are created with good MAC and IP pair information then you go for the spread effect with SPAN. Think of it this way. The ARP and MAC information is very focused like a sniper rifle. The SPAN is like a big net catching the spray of pellets from a shotgun.
After the assets (device IDs) are created, then focus on all the other integrations to add data enrichment. The are integrations that provide user information, application data, endpoint information, etc. Please do not add enrichment integrations (e.g. SCCM, Active Directory, JAMF, InTune, etc) until you have added the ones from the above list first. This will help reduce duplicate device issues.
Centrix does have auto merging but there are limitations.
- We first merge devices that have strong identifiers like ARP and MAC data.
- We next merge by device name but only if both devices are classified as Full Visibility. We do not merge a Limited Visibility (IP address only) with a Full Visibility.
- We can merge by Serial numbers which is good for medical devices.
If you do not start with a good foundation of ARP and MAC, then your tenant will have more duplicate devices. To address this, Centrix has a manual merge feature by name. Each time you do a manual merge the AI learns from this to help future merging.