Network Devices

Scan Network Devices with cnspec

Scan network devices like Cisco, Arista, Juniper, Fortinet, Palo Alto, Check Point, F5, MikroTik, and Ubiquiti against security and compliance best practices with cnspec.

Switches, routers, and firewalls enforce the boundaries of your network, and a single misconfiguration can expose everything behind them. cnspec connects to your network devices and scans their running configuration against security and compliance best practices, without installing anything on the device.

New to cnspec? Read the Quickstart to install cnspec and run your first scan.

Choose your device platform

Looking to scan domains, IP addresses, or open ports instead of device configurations? See Scan Networks and Hosts.

Looking to scan server baseboard management controllers over IPMI or Redfish (including HPE iLO, Dell iDRAC, and Supermicro)? See Scan BMCs.

Scan a fleet of devices at once

Each device page above shows how to connect to one device at a time. Once you're ready to scan more than a handful, list every device and its credentials in an inventory file and scan them all with a single command:

cnspec scan --inventory-file network-fleet.yml

For a worked example that mixes vendors and shared credentials, read Remote Scanning with Inventory Files.

Go further with Mondoo Platform

To continuously monitor your network devices and track posture over time, register cnspec with Mondoo Platform.

On this page