You can add assets from your on-premises Internet Data Center (IDC) to Security Center and centrally manage them in the Security Center console.
How it works
After you install the Security Center agent on a server in your data center, you can create an IDC probe on that server. The IDC probe scans servers within a specified CIDR block at the scan interval that you set. When the probe discovers a server, Security Center automatically adds it to the IDC Probe Finding tab of the page.
Discovered servers are not protected by Security Center. You must install the Security Center agent on these servers to enable protection from Security Center.
-
You can add an IDC probe only to a server in your data center where the Security Center agent is installed.
-
If you have multiple data centers and their networks cannot communicate with each other, you must add an IDC probe in each data center.
Prerequisites
The Security Center agent is installed on a server in your data center. For instructions, see Install the agent.
Add an IDC probe
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
On the tab, click Add Probe.
Alternatively, on the page, hover over the
icon in the Add Multi-cloud Asset section and click Add under IDC. This also opens the Add Assets Outside Cloud panel. -
In the Add Assets Outside Cloud panel, configure the IDC probe settings, and then click Next.
-
Data Center: Enter the name of the data center where the server is located.
-
CIDR Block Settings: Specify the CIDR block that you want the IDC probe to scan.
ImportantOnly CIDR blocks with a /24 prefix are supported, such as 192.168.0.10/24.
-
Period Settings: Select the scan interval for the IDC probe.
-
Linux Port: Specify the SSH port of the Linux servers that the IDC probe scans.
-
Windows Port: Specify the Remote Desktop Protocol (RDP) port of the Windows servers that the IDC probe scans. You can specify a non-standard port.
-
Region: Enter the city where the server is located. This name is displayed as the server's region on the Assets page.
-
-
In the Add Assets Outside Cloud panel, select one or more servers to host the IDC probe, and then click OK.
You must select servers that have the Security Center agent installed and can access the CIDR block you specified in the previous step.
View IDC probe scan results
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
On the Host page, click the IDC Probe Finding tab to view the details and agent installation status of discovered IDC servers.
The following information is displayed:
-
Start Time: The time when the server was discovered.
-
IP Address/Port/CIDR Block: The IP address, port, and CIDR block of the discovered server.
-
Data Center: The name of the data center where the discovered server is located.
-
Agent: The status of the Security Center agent on the discovered server.
-
Asset Finding: The operating system of the discovered server.
-
Probe: The name, public IP address, and private IP address of the probe server.
If the agent status for an IDC server is Unknown, verify whether the agent is installed on the server. To protect the server with Security Center, you must manually install the agent. For instructions, see Install the agent.
-
To exclude an IDC server from scans, add it to the whitelist.
Disable an IDC probe
If you no longer need to use a probe server, you can go to the page to disable or delete the probe server.
After you disable a probe server, Security Center stops scanning servers in that data center, and information about new servers is no longer synchronized to Security Center.
Add a server to the scan whitelist
To exclude a server from probe scans, add it to the whitelist.
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
On the Host page, click the IDC Probe Finding tab to add a server to the scan whitelist.
-
In the list of scan results on the IDC Probe Finding tab, find the server that you want to add to the whitelist, and click Add to Whitelist in the Actions column.
After a server is added to the whitelist, the system stops scanning it and recording its information.
-
On the IDC Probe Finding tab, click Whitelist in the upper-right corner of the scan results list to view the whitelisted scan results.
-
What to do next
-
You can install the agent on the discovered servers in your data center. This enables Security Center's detection and protection capabilities for the servers.
-
You can manage the quota for host and container protection to assign a specific edition to servers in your data center that have the agent installed. This enables the protection capabilities of that edition.