<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Discovery of Firewall in ITOM forum</title>
    <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020557#M92687</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have some Firewalls in our environment. I tried to discover them. These devices are discovered as IP Router. Is there any way to discover them as Firewall ?&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2013 13:33:03 GMT</pubDate>
    <dc:creator>nikhilagr20</dc:creator>
    <dc:date>2013-06-11T13:33:03Z</dc:date>
    <item>
      <title>Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020557#M92687</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have some Firewalls in our environment. I tried to discover them. These devices are discovered as IP Router. Is there any way to discover them as Firewall ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2013 13:33:03 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020557#M92687</guid>
      <dc:creator>nikhilagr20</dc:creator>
      <dc:date>2013-06-11T13:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020558#M92688</link>
      <description>&lt;P&gt;Check out these pages:&lt;BR /&gt;&lt;BR /&gt;http://wiki.servicenow.com/index.php?title=Discovery_Classification_Parameters&lt;BR /&gt;&lt;BR /&gt;http://wiki.servicenow.com/index.php?title=Device_Classifications&lt;BR /&gt;&lt;BR /&gt;Easiest way I've found is to find what value is in the 'sysdescr' portion of the SNMP query and use that to trigger the Firewall classifier and whatever probes you select. Doug has a how-to video on it here:&lt;BR /&gt;&lt;BR /&gt;http://community.servicenow.com/blog/dougschulze/build-simple-snmp-classifier&lt;BR /&gt;&lt;BR /&gt;You may have to create an additional SNMP OID in the system to get it to launch properly though.&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Jun 2013 20:34:50 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020558#M92688</guid>
      <dc:creator>Community Alums</dc:creator>
      <dc:date>2013-06-12T20:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020559#M92689</link>
      <description>&lt;P&gt;To add to that you would want to absolutely add the SNMP System OID that calls the classifier Peyton references above. We are calling it a "router" because it told us it has routing capabilities.&lt;BR /&gt;&lt;BR /&gt;*geeks can look at the Shazzam Sensor to see what we look for in a routing capability*&lt;BR /&gt;&lt;BR /&gt;By adding the SNMP System OID we will basically "ignore" its capability and do what you tell it to do...&lt;BR /&gt;&lt;BR /&gt;This will guide you for sure!&lt;BR /&gt;&lt;BR /&gt;http://tinyurl.com/l42bf83&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Jun 2013 18:13:39 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020559#M92689</guid>
      <dc:creator>doug_schulze</dc:creator>
      <dc:date>2013-06-18T18:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020560#M92690</link>
      <description>&lt;P&gt;Doug,&lt;/P&gt;
&lt;P&gt;Is there an updated version of the&amp;nbsp;http://tinyurl.com/l42bf83 link you'd provided? It seems that link is dead, and I'm having this same thing happen in our environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Will P.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 21:22:52 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020560#M92690</guid>
      <dc:creator>Will Patterson</dc:creator>
      <dc:date>2019-12-16T21:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020561#M92691</link>
      <description>&lt;P&gt;Will, my best guess is that I was probably referencing &lt;A href="https://community.servicenow.com/community?id=community_article&amp;amp;sys_id=dfd86535db172300f21f5583ca9619dc" rel="nofollow"&gt;the videos I did here..Well the first one..&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 02:40:51 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020561#M92691</guid>
      <dc:creator>doug_schulze</dc:creator>
      <dc:date>2019-12-17T02:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020562#M92692</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;This is expected behavior right because if the firewall is hopping from one IP to other and it has routing capability then it will be treated as IP Router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just confirmed with Network guy and he said it is expected behavior. Even in activity log or history of IP field you can see the IP will be changing always.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ashutosh&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 20:36:09 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020562#M92692</guid>
      <dc:creator>Ashutosh Munot1</dc:creator>
      <dc:date>2019-12-17T20:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery of Firewall</title>
      <link>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020563#M92693</link>
      <description>&lt;P&gt;We are in the beginning phases of integrating and testing the Next Generation Firewall patterns, so we are using the OOB Firewall Classifier.&amp;nbsp; We ran into the same issue during discovery where a couple firewalls were being discovered as IP Routers. Our thought process or belief is that this shouldn't be expected behavior.&amp;nbsp; Although firewalls can and do participate with routing the primary &lt;STRONG&gt;function&lt;/STRONG&gt; of a firewall is to apply security policy to and from networks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The OOB classifier uses DNS for Exploration,SNMP-Identity trigger probes and sysdescr contains firewall classification criteria. We also have populated all the SNMP OID Classifications as pointed out in other Community. We have also added the sysdescr does not contain firewall to the Standard Network Router classifier. Why does it bypass and where does it bypass the steps to kick-off the Router Pattern?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we need to modify the Network Router pattern to include that the description does not contain firewall? Or&amp;nbsp;create an isFirewall variable like the Create isRouter?&lt;/P&gt;
&lt;P&gt;1.2 Create&amp;nbsp;isRouter variable&lt;/P&gt;
&lt;P&gt;1.12 Create shouldRunRouterLogic variable&lt;/P&gt;
&lt;P&gt;1.38 Set isRouter variable&lt;/P&gt;
&lt;P&gt;1.40 If it is a router, isPrinter should be false&lt;/P&gt;
&lt;P&gt;1.52 Set shouldRunRouterLogic variable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A walk in the pattern,&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 12:56:10 GMT</pubDate>
      <guid>https://www.servicenow.com/community/itom-forum/discovery-of-firewall/m-p/1020563#M92693</guid>
      <dc:creator>Oneimus</dc:creator>
      <dc:date>2020-07-21T12:56:10Z</dc:date>
    </item>
  </channel>
</rss>

