Connections and credentials
Connections ▸ Connections and credentials (Ctrl+Shift+K) is the one place SubnetSleuth is told how to reach things. The command line reads and writes the same list.
Credentials
Credentials are what SubnetSleuth signs in with. Each is saved once and chosen everywhere else, so one domain service account can serve Active Directory, every DHCP server and host inspection, and changing its password is one edit.
| Kind | Used for |
|---|---|
| SNMP community (v2c / v1) or SNMPv3 user | Scans |
| SSH account (password or key file) | Inspecting Linux and Unix hosts, capturing device configurations |
| Windows / domain account | Active Directory, Windows DNS and DHCP servers, inspecting Windows hosts |
| Web or API sign-in | Firewalls, managers and vCenter that sign in with a user name |
| API key or token | Cloud dashboards, firewalls and AI providers that use a key |
| DNS TSIG key | DNS zone transfers that need one |
Test tries a credential against a device or host before you rely on it.
How secrets are kept
Never in a project file, so a project can be handed to someone else safely. On Windows, secrets are encrypted with
DPAPI, tied to your Windows account. A secret can instead be env:NAME, read from an environment variable each
time it is used. A secret that cannot be read is reported as such and never silently replaced by an empty one.
Credentials go only where they belong
A scan tries only the SNMP credentials ticked for it. A credential limited to networks is never sent anywhere else. Host inspection sends an account only to hosts inside the project's ranges that look like the right kind of system. Every use of a credential is written to the log: which one, for what, against what, never the secret.
Connections
Connections are the systems SubnetSleuth reads from, each with its settings and the credential it signs in with.
| Kind | Sources |
|---|---|
| Cloud dashboards | Cisco Meraki, Cisco Security Cloud Control |
| Firewall managers | Cisco Secure Firewall Management Center, FortiManager, Panorama |
| Firewalls | FortiGate, Palo Alto Networks PAN-OS, Check Point, SonicWall, Sophos Firewall |
| Directory, DNS and DHCP | Active Directory, Windows DNS and DHCP servers, DNS zone transfer |
| Virtualization | VMware vCenter |
| Files | DHCP lease exports |
Test signs in and reads one small thing. Pull reads everything into the open project; Pull all (Ctrl+Shift+P) does every connection marked Include in Pull all. Each source lists the read-only access to ask for, and every request a connector can send is checked against its read-only list before it leaves your computer.
What a pull adds
Platform records are matched to the scan by serial, MAC and address. Network gear the platform manages appears under Network devices; clients are placed on the switch port or access point the platform saw them on; site-to-site tunnels are drawn on the map. When a pull finishes, SubnetSleuth offers to scan what it found: the internal subnets the platform serves join the scan ranges, and the devices it manages are polled. Networks behind a site-to-site tunnel are listed but never added automatically, since a tunnel can lead to a partner's network.