User`s guide

Table Of Contents
VMware, Inc. 47
Chapter 5 Discovery
Choosing a Method of Dependency Discovery
Table 53outlinesthe differencesintheinformationthatarediscoveredthrougheitherPassiveDiscovery(PD)
orDetailDiscovery(DD)tohelpyoudeterminewhichtypetouseinyourenvironment.
NotethefollowingwhenyouareusingPassiveorDetailDiscoveryfordiscoveringdependencies:
IfthesameconnectionisdiscoveredthroughbothPassiveandDetailDiscovery,theconnectionis
reconciledtoappearasasingleconnection;forexample,ifPassiveDiscoverydiscoverstheprotocol,
activityandtheserversideservice,andDetailDiscoverydiscoverstheclientsideservice,thetwo
discoverieswouldbereconciledto
includealltheinformationcollectedbybothdiscoverytypes,without
redundancy.
Theprocessofreconcilinghostsmighttakesometime.
ADMusesthesamePassiveDiscoveryscopeIPfilterstofilterremotehosts(hostsconnectedtothe
interrogatedhost)discoveredduringDetailDiscovery.ThisfeatureavoidstheproblemofDetail
DiscoveryoverridingtheIPrangesthatwereexcludedaspartofthePassiveDiscoveryscope.
Bydefault,DetailDiscoverypoliciesdonotdiscovernetworkdependenciesduetoissuessurrounding
performance.Thediscoveryofnetworkdependenciessubstantiallyincreasestheamountoftimeittakes
toreconcilethediscoveredresults,andsincethedefaultdeploymentofADMincludesPassiveDiscovery,
thisdefaultconfigurationstillprovidesafullview
ofthenetwork,includingnetworkdependencies.
vCollectorsupportPassiveDiscoveryonly.
Discovertheopenportsthattheservices
runningontheinterrogatedhostareusing
tolistenforincomingconnections(“service
endpoints”).
BothnetstatandSNMPtablesexposelisteningportsthatisusedtocreate
aserviceendpointwiththatport.Anexampleofthisisdiscoveringthat
anApacheserviceis
listeningonports80and8080,evenifnoactive
connectionexistsatthetimeofthediscovery.
Guessthetoplevelprotocolusedbythose
connections.
Toavoidfalsepositives,itisdoneonlyonlowports:<512.
Table 5-2. Dependency Discovering Methodology (Continued)
What How
Table 5-3. Comparison of Passive and Detail Discovery Information
Difference
Advantage
PD DD
Detaileddiscovereddependenciesdonotincludeactivity,whereaspassivelydiscovered
dependenciesdo.
ProtocolidentificationisbyfarmoreaccuratewithPassiveDiscovery.Thisofcourse,results
fromPassiveDiscoveryʹsspecializationinprotocolanalysis.
PassiveDiscoveryisweakindiscoveringthesourceofaconnectionforreasonsexplainedin
“A D M
DependencyDiscoveryMethods”onpage 46.
PassiveDiscoverycannotdiscovertheportsonwhichaserviceislisteningunlessaclient
sentapackettoit.
DetailDiscoverydiscoversconnectionsthatareactiveatthetimeofdiscovery,whereas
PassiveDiscoverysamplesallcommunicationtrafficonthenetwork.Thismeansthat
ephemeralconnectionshavelessofachancetobediscoveredthroughDetailDiscovery.
Note:Howevertheconnectionsthatareactiveandrepresentinganinteractionwithalive
businessapplicationarenotlikelytobeephemeral.
OnlyDetailDiscoverydiscoversdocumenteddependenciesthataredependenciesdiscovered
bylookingattheconfigurationof
service,suchasinthefilesandregistry.