OT Discovery deployment scenarios
Summarize
Summary of OT Discovery deployment scenarios
OT Discovery deployment scenarios vary based on the network architecture of your Operational Technology (OT) environment. These scenarios guide how to deploy OT Discovery components—Discovery Console for OT, Discovery Sensor for OT, and OT Discovery Collector—to effectively discover and manage OT assets across different network designs.
Show less
General recommendations
Deployment guidance depends on factors such as network segmentation, communication pathways, traffic, redundancy, and environmental conditions. While generalizations are provided, your specific network setup should influence exact deployment choices. For detailed resource requirements, refer to OT Discovery System Resources documentation.
Deployment scenarios
Flat network architecture across multiple sites
- All Discovery components connect within a single network allowing direct communication.
- A single Discovery Console for OT can cover multiple sites, deployed where the MID Server can access both the Console and the ServiceNow instance.
- Discovery Sensors are deployed to optimize discovery speed and can reach all OT assets within the flat network.
- This setup simplifies communication at Purdue level 3.5, pushing discovery data through switches and firewalls to ServiceNow.
Multiple independent segmented sites
- The network is divided into isolated segments, each with its own Discovery Console for OT and multiple Sensors and Collectors.
- Segments operate as independent flat networks without inter-site communication, enhancing security and operational clarity.
- Each segment’s Console manages credentials and discovery locally, and Sensors perform active discovery and protocol queries like Modbus, DNP3, and BACnet.
- Consoles and Sensors reside within their respective network zones without direct internet access, maintaining isolation.
Micro-segmented site with multiple networks
- Networks are subdivided into multiple segments, each with dedicated Discovery Console for OT and Sensors.
- Sensors are deployed in each segment to actively discover assets, collect traffic, and query protocols, reporting to the local Console.
- OT Discovery Collector can be installed on existing hosts such as Human Machine Interfaces (HMI) or Engineering Workstations (EWS) to perform discovery tasks.
- Ensure Sensors and Collectors have communication pathways to their respective Consoles for data reporting.
Practical implications for ServiceNow customers
Understanding these deployment scenarios helps you design an OT Discovery architecture aligned with your network’s segmentation and security needs. Properly deploying Consoles, Sensors, and Collectors ensures efficient and secure discovery of OT assets, enabling comprehensive visibility and management through ServiceNow. Selecting the appropriate scenario and deployment strategy supports faster discovery, enhanced security, and accurate asset data ingestion into your ServiceNow instance.
Deployment scenarios for OT Discovery vary based on a network's architecture. Use these scenarios to help determine how to deploy the OT Discovery components in your OT environment.
General recommendations
General recommendations and guidance are listed in each scenario in these sections. Not all networks are the same. The requirements in this section are a generalization for the scenario. Consider factors such as segmentation level, communication pathways, network traffic, redundancy, and environmental conditions. For resource recommendations for the OT Discovery components see, OT Discovery System Resources.
Flat network architecture across multiple sites
A flat network architecture is a network design that has all available Discovery Console for OT, Discovery Sensor for OT, and OT Discovery Collector connected to a single network, where the Sensors and Collectors can communicate with each other directly.
The Console, Sensors, and MID Server connect at Purdue level 3.5 and push data through the switches and the firewall to the ServiceNow instance for ingestion.
Components in the flat network
- Discovery Console for OT and Discovery Sensor for OT.
- A localized appliance or VM that serves as the command-and-control interface for asset discovery and communication in its respective segment. This appliance or VM manages credentials, protocol handlers, and initiates querying operations locally. In such a scenario, a typical deployment means that one Console covers multiple sites.
- Deploy the Console at a layer where the MID Server can connect to the Console and the ServiceNow instance.
- Deploy Sensors based on the desired speed of the discovery. In a truly flat network, a Discovery Sensor for OT can reach all the OT assets in that network. More Sensors in the network can help improve the speed of discovery.
Multiple independent segmented sites
A segmented site architecture is a network design that has the network split into multiple segments. Each segment contains its own Discovery Console for OT and multiples of the Discovery Sensor for OT and the OT Discovery Collector. There is no communication between sites. Each of the segments could be considered a flat network.
- Site 1 Operational Technology segment
- Site 2 Operational Technology segment
- Physical Security Network segment
- Discovery Console for OT or VM that serves as the command-and-control interface for asset discovery and communication in its respective segment. It manages credentials, protocol handlers, and initiates scanning operations locally.
- Discovery Sensor for OT is deployed in each segment. The Sensor performs active discovery, collects network traffic, and queries for known protocols (for example, Modbus, DNP3, BACnet). It reports findings to its segment's Console.
The Consoles and Sensors are deployed in their respective network zones and don't have direct outbound access to the internet.
Micro-segmented site with multiple networks
- Make sure the Sensors and Collectors have a communication pathway to the Console.
- Deploy Sensors in each segment where the Sensor can perform active discovery in the segment and collect network traffic and can scan or query for known protocols (for example, Modbus, DNP3, BACnet). It reports findings to its segment's Console.
- If you use an existing host to do the discovery in the network such as Human Machine Interface (HMI) or Engineering Workstation (EWS), you can install the OT Discovery Collector to perform discovery.