Network Connections
Use the Network Connections page to see a consolidated view of all network connections between assets in your environment. The Network Connections page delivers visibility into communication patterns, helping security, IT, and risk teams identify risky connections, understand traffic flows, and support network segmentation initiatives.
Network Connections are discovered through CPA (Cyber Physical Assets), which integrates with your network through passive Collectors connected to network switches via a SPAN port. This approach provides a copy of network traffic to CPA, which discards sensitive payload data while identifying characteristics relevant to the security posture of assets, such as source and destination asset, protocols, and ports. Both standard IT protocols and industrial and medical protocols (such as Modbus, DICOM, and EtherNet/IP) are identified. Because collection is entirely passive, there are no agents to deploy and no active scanning that could disrupt sensitive OT devices. The result is identification of risky communication patterns and the foundation for CPA to resolve issues through segmentation mappings and customized network policies for each segment.
To view a graph of a device's network connections, see Device Network Connection Graph.
To access the page:
- From the Assets menu, expand Network and select Network Connections.
Note
Conversations with identical characteristics (for example, source asset, destination asset, protocol) are treated as a single Network Connection.
Network Connections Fields
Fields displayed on the Network Connections page include:
- Adapter Connections - Shows the adapter connections from which the Network Connection was discovered. Hover over the Adapter Connections column to see the adapter names for all adapter connections.
- Srce IP - The asset initiating the network connection. Click the source asset to open its Asset Profile page.
- Srce.Type - The type of device that initiated the network connection (for example, IP Camera, IoT Device, or PC), as identified by the Network Inspector from observed network traffic.
- Src. Device Model - The model of the device that initiated the network connection, as identified by the Network Inspector from observed network traffic. The field is empty if the model cannot be determined.
- Dest. IP - The asset receiving the network connection. Click the destination asset to open its Asset Profile page.
- Dest. Type - The type of device that received the network connection (for example, IP Camera, IoT Device, or PC), as identified by the Network Inspector from observed network traffic.
- Dest. Device Model - The model of the device that received the network connection, as identified by the Network Inspector from observed network traffic. The field is empty if the model cannot be determined.
- Protocol - The network protocol used for the connection (for example, TCP, UDP, ICMP).
- Last Seen - The timestamp when the connection was last observed in the network.
- Source Port - The port number on the source asset from which the connection originates.
- Destination Port - The port number on the destination asset to which the connection is directed.
- Connection Type - Classifies each connection into one of the following categories:
- Internal - Communication between two assets within your internal network.
- External-Incoming - Communication from an external source to an internal asset.
- External-Outgoing - Communication from an internal asset to an external destination.
Not all available fields are displayed by default. Use Edit Columns to add or remove columns. See Setting Page Columns Display for more information.
Filtering Network Connections
You can create queries on the Network Connections page to filter and analyze specific connection patterns. You can create queries on Network Connections using the Basic mode - Create a query by selecting filters. Learn more and how to create Queries in Basic mode.
Use queries to identify specific connection patterns, such as:
- All external/outgoing connections to cloud services
- Connections using specific protocols or ports
- Connections to or from specific assets
- Connections last seen within a specific time range
Related Information
- Network Overview - Learn about all Network asset types
- Network Inspector Deployment - Learn about deploying the Axonius Network Inspector device
- Network Inspector Functionality - Learn about the Network Inspector device functionality
Updated about 1 hour ago
