Host Information: Tracking Method

Every host in the subscription is assigned a tracking method: IP address, DNS Hostname or NetBIOS hostname. The assigned tracking method determines how the host will be reported in scan reports. Hosts assigned a tracking method of DNS hostname or NetBIOS hostname will be listed in alphabetical order by hostname. Hosts assigned a tracking method of IP address will be listed in numerical order by IP address. Initially, all hosts are tracked by IP address.

 

Changing the tracking method

Note the following when changing the tracking method.

DNS and NetBIOS tracking methods are only available when certain information is known:

You can only change the tracking method to DNS or NetBIOS hostname if the hostname was already resolved for the host in a previous scan. You can assign any tracking method to hosts that have never been scanned and hosts that have been purged.

If you track a host by DNS or NetBIOS hostname and the hostname is not resolved during a scan, then vulnerability information for the host will not be reported in your scan results. The host will be listed in the "Hosts Not Scanned" appendix under "Hostname Not Found". Note that this appendix only appears in single saved scan results, viewable from the scan history list or by running a manual scan template and only selecting one scan result.

IP address may be resolved to more than one hostname:

If a host's IP address is resolved to two or more hostnames in different scan tasks and you are tracking by DNS or NetBIOS hostname then each hostname is listed as a separate host in your hosts list and in scan reports. Thus, the same IP address will appear multiple times. If you change the tracking method for such a host to IP address, then the most recent scan data for the IP will be saved and old scan data must be purged.

For example, during a scan of IP 10.10.10.1 on 10/3, the hostname detected is HOSTA. During a scan of this same IP a month later on 11/3, the hostname detected is HOSTB. If you change the tracking method to IP address for either of these hosts, then host information from the older scan on 10/3 will be purged and host information from the more recent scan on 11/3 will be saved.

 

Scanning hosts tracked by DNS or NetBIOS

To properly scan a host tracked by DNS or NetBIOS hostname, the service must be able to resolve the target IP address to a hostname. If the hostname is not resolved, then the host will not be scanned and security audit results will not be reported.

To scan NetBIOS tracked hosts, include UDP port 137 in the scan options applied to the task. This port is automatically included when the "Scanned UDP Ports" option is set to Standard Scan, Light Scan or Full in your option profile.

To scan DNS tracked hosts, make sure that your DNS servers are configured to communicate with scanners (external scanners and/or scanner appliances), and that your DNS servers can resolve the target IP addresses to hostnames. Note that IP addresses for external scanners appear on the Account Info page (Help > Account Info).