<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOT SNMP Queries using Xsoar and L3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503280#M105411</link>
    <description>&lt;P&gt;I know the engineer that got this feature built during a PoC. He is on vacation but I've sent this his way to get clarification for you. Will follow up when he does.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2022 00:58:08 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2022-06-14T00:58:08Z</dc:date>
    <item>
      <title>IOT SNMP Queries using Xsoar and L3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/486406#M104603</link>
      <description>&lt;P&gt;I see that snmp queries can be used to discover devices for IOT using xsoar engines.&amp;nbsp; I also see that it uses cdp lldp and gathers arp and mac data.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/iot/iot-security-integration/network-management/integrate-iot-security-with-network-switches-for-snmp-discovery" target="_blank"&gt;https://docs.paloaltonetworks.com/iot/iot-security-integration/network-management/integrate-iot-security-with-network-switches-for-snmp-discovery&lt;/A&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;Specifically in the documentation:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;The XSOAR engine also queries the entry &lt;STRONG&gt;switch for the IP addresses of neighboring switches on the network&lt;/STRONG&gt;. It collects device information from them next and also gets a list of their neighboring switches as well. XSOAR continues collecting device information and learning about other switches until it has queried them all.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What I don't understand is what happens when this engine hits a L3 boundary.&amp;nbsp; Does the discovery continue past/through an MPLS network, or is it simple snmp queries, and will it fail past a routed MPLS connection, not discovering other networks/routers?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 16:34:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/486406#M104603</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2022-05-11T16:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: IOT SNMP Queries using Xsoar and L3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503280#M105411</link>
      <description>&lt;P&gt;I know the engineer that got this feature built during a PoC. He is on vacation but I've sent this his way to get clarification for you. Will follow up when he does.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 00:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503280#M105411</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-06-14T00:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: IOT SNMP Queries using Xsoar and L3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503631#M105442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also wonder how far it goes switch wise.&amp;nbsp; &amp;nbsp;Does it stop at the distribution switch, or does it go to the access layer switch, and what triggers it to go further?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 17:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503631#M105442</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2022-06-14T17:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: IOT SNMP Queries using Xsoar and L3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503655#M105446</link>
      <description>&lt;P&gt;Spoke with the dev that made the feature. You configure the snmp crawl profile, it will reach out to that switch you configure it for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there, it will use LLDP to go switch to switch, up to 5 layers (we can change this if need be). The LLDP discovery gives MAC to port binding (so we know which next targets to find), and after the crawler has exhausted LLDP switch discovery, it will then request ARP tables from each switch to populate MAC to IP for IoT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He doesn't wish to share how the crawler itself functions in the network, but, that he will show it in PoC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can create multiple SNMP profiles, and will need to for each subnet/segment of the network. That is to say, it won't crawl any L3 boundaries.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 18:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503655#M105446</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-06-14T18:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: IOT SNMP Queries using Xsoar and L3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503807#M105461</link>
      <description>&lt;P&gt;I've noticed in some cases it never gets past the distribution switch, that is not 5 hops away.&amp;nbsp; &amp;nbsp;Seems like it stops there, while others it goes all the way down to the access switch.&amp;nbsp; Just not sure what would cause that.&lt;BR /&gt;&lt;BR /&gt;Either way- that is spectacular feedback.&amp;nbsp; Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 13:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/iot-snmp-queries-using-xsoar-and-l3/m-p/503807#M105461</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2022-06-15T13:32:52Z</dc:date>
    </item>
  </channel>
</rss>

