Captured data
Each DNS server becomes an asset of the type DNS with three groups:
How the detail page of the type is structured is described in
Directory and Network Services.
Setting up the job
The wizard follows the standard path Basics › Targets › Schedule › Summary—see Creating a Scan Job. The Targets step is what sets this module apart. Each row carries the columns Server Name and Credentials. Server Name takes one DNS server per row, as an address or hostname; the column does not accept an address range. Search DNS Servers fills in the servers from Active Directory instead: the dialog asks for the Domain and credentials and adds the DNS servers it finds as rows, including the servers in child domains. The Credentials column may stay empty. The scan then runs under the gateway’s service account, and that account needs the rights listed under Permissions. An entry in Credentials for all targets applies to every row without an assignment of its own.Prerequisites
The scan connects to the DNS servers over WMI and queries the DNS data through PowerShell.Ports and protocols
Permissions
- On the DNS servers the account needs domain administrator rights.
- Enter the account with the domain:
DOMAIN\useroruser@domain.local.
Network requirements
- The firewall allows the ports above.
- The DNS servers have:
- .NET Framework 4.6.1 or later,
- PowerShell 3 or later, allowed to run,
- the PowerShell module for DNS,
- access to
C:\Windows\Tempand to theIPC$share.
Discovery-DNS.exe scan script—see
Scanning by Script.