PLEASE READ THE FOLLOWING MESSAGE CAREFULLY BEFORE INSTALLING AND USING THIS PRODUCT. THIS PRODUCT IS COPYRIGHTED
PROPRIETARY MATERIAL OF PEREGRINE SYSTEMS, INC. (“PEREGR INE”). YOU ACKNOWLEDGE AND AGREE THAT YOUR USE OF THIS PRODUCT
IS SUBJECT TO THE SOFTWARE LICENSE AGREEMENT BETWEEN YOU AND PEREGRINE. BY INSTALLING OR USING THIS PRODUCT, YOU
INDICATE ACCEPTANCE OF AND AGREE TO BE BOUND BY THE TERMS AND CONDITIONS OF THE SOFTWARE LICENSE AGREEMENT BETWEEN
YOU AND PEREGRINE. ANY INSTALLATION, USE, REPRODUCTION OR MODIFICATION OF THIS PRODUCT IN VIOLATION OF THE TERMS OF THE
SOFTWARE LICENSE AGREEMENT BETWEEN YOU AND PEREGRINE IS EXPRESSLY PROHIBITED.
Information contained in this document is proprietary to Peregrine Systems, Incorporated, and may be used or disclosed only with written
permission from Peregrine Systems, Inc. This book, or any part thereof, may not be reproduced without the prior written permission of
Peregrine Systems, Inc. This document refers to numerous products by their trade names. In most, if not all, cases these designations are
claimed as Trademarks or Registered Trademarks by their respective companies.
Peregrine Systems, AssetCenter, AssetCenter Web, BI Portal, Dashboard, Desktop Inventory, Get-It, Network Discovery, Peregrine Mobile, and
ServiceCenter are registered trademarks of Peregrine Systems, Inc. or its subsidiaries.
Microsoft, Windows, Windows 2000, SQL Server, and names of other Microsoft products referenced herein are trademarks or registered
trademarks of Microsoft Corporation. The information in this document is subject to change without notice and does not represent a
commitment on the part of Peregrine Systems, Inc. Contact Peregrine Systems , Inc., Customer Support to verify the date of the latest version
of this document. The names of companies and individuals used in the sample database and in examples in the manuals are fictitious and
are intended to illustrate the use of the software. Any resemblance to actual companies or individuals, whether past or present, is purely
coincidental. If you need technical support for this product, or would like to request documentation for a product for which you are licensed,
contact Peregrine Systems, Inc. Customer Support by email at support@peregrine.com. If you have comments or suggestions about this
documentation, contact Peregrine Systems, Inc. Technical Publications by email at doc_comments@peregrine.com. This edition of the
document applies to version 5.2.3 of the licensed program.
Peregrine Systems, Inc.
3611 Valley Centre Drive San Diego, CA 92130
Thank you for using Network Discovery. This book is intended for the Network
Discovery Administrator, the person who will have the most control over the
setup and operation of Network Discovery.
This information is critical to your success with Network Discovery. Your sales
representative may have given it to you as a separate pre-purchase handout
(Preparing for Installation); or you may be seeing it for the first time as the first
four chapters of the Network Discovery Setup Guide. The information is exactly
the same. If you have seen the information before and have already done the
preparation, you can go to Chapter 5, Install and Start Network Discovery. If you
are seeing this information for the first time, let’s get started.
Important: Instructions for upgrading from Network Discovery 5.0, 5.0.1, 5.0.2,
5.1, 5.1.1, 5.1.2, or 5.2 are in the 5.2.3 Release Notes.
About Network Discovery
Network Discovery is a real-time web-based network manager. When
integrated into your network, Network Discovery will discover and monitor all
devices in your network. You will use Network Discovery to find, diagnose and
solve network problems.
Welcome to Network Discovery | 11
Network Discovery
Peregrine Desktop Inventory can contribute data to Network
Discovery
Peregrine Desktop Inventory (PDI) scanners can be scheduled from Network
Discovery and scan files can be added to a shared directory on the Peregrine
appliance, so the scanned devices will appear in the Network Discovery
database, and on the Network Map.
For more information on setting up PDI to contribute data to Network
Discovery, see Using Network Discovery with Desktop Inventory and Desktop Administration.
Why it’s important to prepare
Setting up Network Discovery is quick and easy, provided you properly prepare
your network, and use the specified equipment for the Peregrine appliance and
the management workstation.
To operate correctly, Network Discovery needs a constant supply of accurate
data. To ensure that Network Discovery knows where and how to collect that
data, you must do a little preliminary work. You only have to do this once.
The complete physical connectivity of your network can only be portrayed
accurately when:
all community strings are provided to Network Discovery
all network connectivity devices are SNMP managed
no network devices use proxy ARPing
no critical entries appear in the Network Exceptions report
If devices do not conform to the standards or fail to respond correctly and
consistently to SNMP polls, Network Discovery may not be able to create an
accurate inventory.
12 | Welcome to Network Discovery
Setup Guide
Start by collecting information about your network
The Pre-Setup Questionnaire is available in the next chapter of this manual (see
Pre-setup Questionnaire on page 15), from your sales representative, or as a
Word file from http://support.peregrine.com.
Note: If you wish, you may fill in the questionnaire and send it to Peregrine
customer support. They can review your information and provide
feedback on how you set up Network Discovery.
If you have already filled out this form and sent it in to Peregrine customer
support, collecting all the information is done. Keep the completed
questionnaire handy.
The questionnaire is designed to make the setup and use of Network Discovery
as smooth as possible. Please answer all questions. Peregrine Systems
recognizes that some information may be considered secure or private, but
providing the information will allow us to create the optimal inventory and
management environment. If you need help filling out the questionnaire, please
contact your Peregrine or OEM/VAR (Original Equipment Manufacturer or Value
Added Reseller) sales representative or contact Peregrine Systems Inc.
Current details of local Peregrine customer support offices are available through
Peregrine’s CenterPoint Web site at http://support.peregrine.com.
When you have completed the questionnaire, send it to Peregrine Systems Inc.
by e-mail, mail or by fax. To find the mailing address or fax number of the
Peregrine office in your region, contact your OEM/VAR or check
http://support.peregrine.com.
Start by collecting information about your network | 13
Network Discovery
14 | Welcome to Network Discovery
2
CHAPTER
Your contact information
Your Name
Organization
Address
Telephone
E-mail
Pre-setup Questionnaire
Fax
Describe your network’s node and subnet setup
Enter the following information to help determine the scale of your network.
Pre-setup Questionnaire | 15
Network Discovery
Note: Network Discovery defines a node as any network device with at least one
MAC address. A managed device is a network device that has an SNMP
agent and MIB so it can respond to SNMP requests.
How many nodes do you believe are active on your network?
Are there any remote sites to be managed?
If yes, approximately how many managed nodes are at remote sites?
Is your network divided into subnets?
If yes, how many subnets does your network contain?
__________
Yes ________ No________
__________
Yes ________ No________
__________
Enter the Peregrine appliance network information
Enter the information that you will assign to the Peregrine appliance at startup.
Note: You will give this IPv4 address to new users so they can log in easily.
Note: If your network uses DHCP, ensure that the IP address for the Peregrine
appliance is static.
Planned IPv4 address for
your Peregrine appliance _______________________________________________________
Default gateway IP address _______________________________________________________
16 | Pre-setup Questionnaire
Peregrine Systems Customer Support access
Information on the options you have for receiving Customer Support is in
Choose how to receive Peregrine Systems Customer Support on page 27.
If you will use a modem and a dedicated analog telephone line, enter the
number of the telephone line.
Setup Guide
Telephone number for access by
Peregrine Systems Customer Support
List IPv4 ranges for Network Discovery to discover
Network Discovery uses IPv4 ranges to discover the devices in your network. It
works best when you give it a broad idea of where the devices in your network
are—but exclude ranges where you know there are no devices.
Note: While you are making a list of devices in your networks, indicate bridges,
routers, switches, and concentrators, so that you can identify them easily.
Please add the IPv4 ranges you want Network Discovery to discover in your
network. For example, to discover an entire class C subnet with subnet mask
255.255.255.0 enter an IP range from xxx.xxx.xxx.0 to xxx.xxx.xxx.255 such as
172.17.1.0. to 172.17.1.255. If you require more space, please attach additional
sheets as needed.
Important: When you assign IPv4 ranges, be aware of the size of the ranges you
are requesting. If you request a large range of IPv4 addresses to
sweep, it can take several hours or days.
FromTo
IPv4 range 1
IPv4 range 2
IPv4 range 3
Peregrine Systems Customer Support access | 17
Network Discovery
FromTo
IPv4 range 4
IPv4 range 5
IPv4 range 6
List IPv4 ranges for Network Discovery to avoid
If there are subsets of the above IPv4 ranges that you do not want Network
Discovery to discover, enter them here.
Important: You do not need to enter ranges outside the ranges you have
specified. Network Discovery does not discover ranges unless you
specify them.
FromTo
IPv4 range 1
IPv4 range 2
IPv4 range 3
IPv4 range 4
List the community strings of your network’s devices
For an explanation of community strings, see About community strings on
page 25.
This is a list of non-directed community strings. Directed community strings are
covered later.
Does Network Discovery need to know the write string?
No. Network Discovery will operate without write strings. However, if you do
give Network Discovery the write strings, the owner of an Administrator
18 | Pre-setup Questionnaire
Setup Guide
account will be able to manage the device from the Network Discovery
interface.
.
Rights granted
Community stringAssociated device /IPv4 rangeReadWrite
Enter TCP/IP configuration
The Peregrine appliance must have its own static IP address, but it can manage
devices with either static or dynamic IP addresses. Please enter the following
information to show how the devices on your network receive IP addresses.
Are TCP/IP addresses static or dynamic?
If dynamic, enter the following:
— The IPv4 address(es) of Dynamic Host
Configuration Protocol (DHCP) server(s)
— The DHCP IPv4 address lease time
(Peregrine Systems recommends a lease time of at
least 7 days.)
Static_________ Dynamic_________
_____________________________________
_____________________________________
_______________________
Enter TCP/IP configuration | 19
Network Discovery
Are TCP/IP addresses static or dynamic?
Is SNMP management enabled on the DHCP
server?
Enable SNMP management on the DHCP server so that Network Discovery can poll the DHCP
server ARP cache for the current IP and MAC address pair information of the devices on your
network.
Static_________ Dynamic_________
Yes ________ No________
Note: Please list the IP addresses of any routers you want Network Discovery to
monitor, that do not have SNMP management enabled now and will not
have management enabled in the future (for example, a router controlled
by an Internet Service Provider).
Unmanaged router number 1
Unmanaged router number 2
Unmanaged router number 3
__________________________________
__________________________________
__________________________________
20 | Pre-setup Questionnaire
Setup Guide
What server will you use for the Peregrine appliance?
Warning: Do not mirror your hard drives, and do not install RAID in your
Peregrine appliance. If you do, your appliance will not function
properly.
Please check one (for more information, see Compatibility Matrix on page 33):
Server TypeCheckmark
IBM xSeries 335
Small - 2GB, 1 CPU________
Large - 4GB, 2 CPUs________
IBM xSeries 330
Small - 1GB, 1 CPU________
Medium - 2GB, 2 CPUs________
IBM xSeries 336
Large - 4GB, 2 CPUs________
IBM xSeries 345
Small - 1GB, 1 CPU________
Dell 1750 Servers
Small - 2GB, 1 CPU________
Large - 4GB, 2 CPUs________
Dell 1650 Servers
Small - 1GB, 1 CPU________
Medium - 2GB, 2 CPUs________
Dell 1850 Servers
Medium - 2GB, 1 CPU________
Dell 2650 Servers
Large - 4GB, 2 CPUs________
HP DL360
What server will you use for the Peregrine appliance? | 21
Network Discovery
Server TypeCheckmark
Large - 4GB, 2 CPUs________
HP DL380
Large - 4GB, 2 CPUs________
Note: Any of the “Large” appliances can be turned into a “Medium” appliance by
removing 1 CPU and 2 GB of RAM.
Send the questionnaire
When you have completed the questionnaire, send it to Peregrine Systems Inc.
by e-mail, mail or by fax. To find the mailing address or fax number of the
Peregrine office in your region, contact your OEM/VAR or check
http://support.peregrine.com.
Current details of local Peregrine Systems Customer Support offices are
available through Peregrine’s CenterPoint Web site at
http://support.peregrine.com.
22 | Pre-setup Questionnaire
3
CHAPTER
Prepare the network
The following flowchart shows all the important tasks that must be completed
to prepare your network. There are other optional tasks described throughout
the chapter.
Enable SNMP management
in network devices
Set DHCP lease time
Configure directed community
strings
Adjust bridge aging
Plan where to connect the
appliance
Configure connection to
customer support
Enable firewall ports
Check other devices and CIR
values
Prepare the network | 23
Network Discovery
Turn on SNMP management in all routers and core
switches
Depending on the device, this may be a case of enabling an existing SNMP
agent or setting up an SNMP agent.
You may also turn on SNMP management in other devices. The more managed
devices in your network, the better. However, enable switches and routers first.
Note: If you use HSRP (Hot Standby Routing Protocol) in your network, ensure
you turn on SNMP management in all the affected devices.
What if you don’t turn on SNMP management in your switches and routers?
Network Discovery will appear to work, but you’ll eventually notice that it is
working poorly. Once Network Discovery is up and running, the Exceptions
reports can advise you of problems. Much of the information that Network
Discovery collects comes from the SNMP MIB of devices in your network, so
it is crucial that you enable SNMP management.
How do you turn on SNMP management?
The exact procedure is different for every device. Consult the documentation
that came with your switch or router.
Note: When you turn on SNMP management in a device, you often assign a
community string. If you assign a new string later, be sure you give the
community string to the Peregrine appliance. For more information, see
About community strings on page 25.
(Optional) Turn on SNMP management in other devices
Your decision to turn on SNMP management in your remaining switches, hubs,
servers and workstations depends on the results you expect from Network
Discovery. For example, in many networks, monitoring the performance of
workstations is not important.
24 | Prepare the network
Set DHCP lease time
If you use DHCP (Dynamic Host Configuration Protocol) in your network, set the
IP address lease time to at least 7 days and turn on SNMP management on the
DHCP servers.
About community strings
A community string is like a password. A device uses a community string to
protect its SNMP MIB—and it’s the data from the SNMP MIB that Network
Discovery relies on. Network Discovery must know at least one of a device’s
passwords to collect data from that device. If you do not give Network Discovery
a device’s community string, Network Discovery will behave as though the
device does not have SNMP management turned on. Network Discovery will
appear to work, but you’ll eventually notice that it is working poorly. Once
Network Discovery is up and running, the Exceptions reports can advise you of
problems.
Setup Guide
Note: Community strings are case-sensitive. “Public” and “public” are two
different strings.
Directed community strings
Directed community strings give devices another layer of protection: a list of IP
addresses of approved devices. When Network Discovery tries to get
information from a device with a directed community string, the device asks not
only “What’s the password?” but also “Are you on the list?”
Give the Peregrine appliance IP address to all devices
using directed community strings
When directed community strings are used, it is not enough to give Network
Discovery access to the device. You must also configure the device to recognize
the Peregrine appliance. You must put it on the list of approved devices.
Set DHCP lease time | 25
Network Discovery
What happens if a device with directed community strings is not configured
with the IP address of the Peregrine appliance?
Network Discovery will behave as though the device does not have SNMP
management turned on. Network Discovery will appear to work, but you’ll
eventually notice that it is working poorly. Once Network Discovery is up and
running, the Exceptions reports can advise you of problems.
(Optional) Adjust bridge aging
To improve the reliability and speed of Network Discovery, adjust bridge aging
on your bridges, routers, switches, and concentrators. Turn bridge aging on, and
set the bridge aging interval to 2-6 hours. Smaller networks can use shorter
intervals; larger networks will need longer intervals. Network Discovery’s
Exceptions reports can tell you which devices should have their bridge aging
adjusted.
Plan the device and port to which the Peregrine
appliance will be attached
Plan to attach the Peregrine appliance:
behind your corporate firewall
to an Ethernet port on a device close to the top of your network. Network
Discovery works best if the port is SNMP managed.
Note: Attach a management workstation to the same device as the Peregrine
appliance. This will make the setup process smoother. It also ensure that
the management workstation does not become isolated from Network
Discovery in the event of device failures.
26 | Prepare the network
Setup Guide
Choose how to receive Peregrine Systems Customer
Support
Options for allowing Customer Support access (in the order in which Peregrine
Systems recommends them) are as follows:
through Internet access
through a Virtual Private Network over Internet
by a modem and a dedicated analog telephone line
through a Remote Access Server (RAS)
Through Internet access
For you to have Customer Support by means of the Internet you must enable
certain ports in the corporate firewall. Peregrine Systems Customer Support
requires access for the following IP address: 209.167.240.9
(ottongw.peregrine.com).
Used forPortNote
Secure Shell (SSH)22/tcp
HTTP80/tcp
MIB browser8100/tcp
Network Map8101/tcp
Network Map proxy8102/tcp1,2
MIB browser proxy8103/tcp1
Telnet proxy8104/tcp1
HTTP proxy8105/tcp1
MySQL ODBC8108/tcp
Choose how to receive Peregrine Systems Customer Support | 27
Network Discovery
Used forPortNote
Applet Server8109/tcp
1. Depending on your settings for Appliance proxy services
2. If you have an Aggregator license
Virtual Private Network over the Internet
Contact Peregrine Systems Customer Support to send them the software that
will enable access. If you have a firewall, enable the firewall ports listed in the
above table.
By modem and dedicated telephone line
For customer support by way of a modem, assign a dedicated telephone line for
the Peregrine appliance. Peregrine Systems will use this line for connection to
the Peregrine appliance during its normal operation (not just during setup). An
internal modem and an analog telephone line allow you to have access to
Customer Support even when you cannot use the Internet.
Note: Keep this line available for use by the Peregrine appliance 24 hours a day,
365 days a year. Peregrine Systems cannot provide you with modem
support unless it has access to your Peregrine appliance.)
Instructions for purchasing a modem and attaching the hardware are in chapter
5, Install and Start Network Discovery on page 45.
Through a Remote Access Server (RAS)
Contact Peregrine Systems Customer Support to send them the IP address or
telephone number that will enable access. If you have a firewall, enable the
firewall ports listed in the above table.
Enable firewall ports
Enabling these firewall ports is not just to allow access to Customer Support on
the Internet; it is to enable any Network Discovery system to perform through a
corporate firewall.
28 | Prepare the network
If you have a corporate firewall that could impede Network Discovery, configure
the corporate firewall to allow ICMP (ping) to pass through, and enable the
following ports: