Generate Alarm Policy for New Devices

You should generate an alarm policy for new devices detected on your wired network by following these steps:

After enabling monitoring, select the New device detected on the wired network checkbox.

Click to expand in new window

To authorize all detected devices for the first time, or at any major infrastructure change, click on the Mass Wired Network Device Classification button.

Click to expand in new window

The Sanction Devices dialog opens.

Click to expand in new window

Select all the vendors you recognize as authorized and permanent for that site. (Help text is provided just above the Mass Wired Network Device Classification button.) Then, sanction devices detected at your site by clicking OK.

To have a finer control over alarms about new known vendor devices and new unknown vendor devices, you can utilize the Known Vendors classification tool. Click on the Known Vendors button to display a list of known vendors.

Click to expand in new window

Select the approved vendors and click OK.

After configuring the Wired Network Monitoring options, click the Apply button to save your changes. Click the Reset button to discard your changes.

Once new devices are detected at your site, you will receive one of two alarms: New Wired Device Detected Known Vendor or New Wired Device Detected Unknown Vendor. Below is a screen shot of Alarm Configuration, where you can customize the criticality, duration, state and exception for each of the alarms.
Click to expand in new window