# Network Security Scans

The Domotz Security feature gives you insights on potential threats to your network:

Security Tab in Domotz Help-Center

1. Navigate to the top menu and select the "Security" tab to access security features.

2. On the left panel, under "Network Logs," you will find "Device Discovery," which shows devices that joined or re-joined the network. It currently indicates no new devices were discovered in the past 24 hours.

3. Below "Security Status," "TCP Open Port Scanner" is listed as "Disabled," and "UPnP Port Forwarding Scanner" is shown as "Enabled."

4. The central panel displays "Device Discovery" details, providing a log of devices with activity dates and network participation.

Use these features to monitor network security by checking device activity and scanner status.

In particular, it provides the following information:

- Latest devices joining the network
- All Open TCP Ports on the WAN side
- Status of UPnP configuration at gateway level and attempts of leveraging that protocol

From this section, users can both review all the potential threats discovered or configuring alerts related to these perimeter scans.

## Network Logs - Device Discovery

This section will report all the devices discovered on the network in the last 60 days, starting from the most recent ones:

Device Discovery Page Layout

1. Open the "Security" tab from the main navigation bar at the top.
2. In the sidebar on the left, click "Device Discovery" under "Network Logs" to view recent devices that have joined or re-joined the network.
3. The main section shows devices grouped by date, with the most recent entries listed first.
4. Each device entry displays the date and time discovered, device name, status (e.g., "Reappeared" or "New Device"), manufacturer (if available), and IP address.
5. If no new devices are discovered on the current day, a message will indicate this.
6. Use this section to monitor network changes and manage device connections efficiently.

This information is very useful in order to understand if recently any un-expected device joined the network by acquiring an IP address.

## Security Status - TCP Open Port Scanner (WAN Side)

When enabled, [Domotz](https://www.domotz.com) performs periodical TCP Port Scans from the Domotz Cloud against the public IP address of the network monitored (WAN IP Address).

The automatic periodical scans are performed with a quite slow process so that most automatic intrusion detection systems (IDS) are not capable of blocking the requests from the Domotz Cloud, increasing the accuracy of the scan.

The automatic TCP open port scanner can be enabled inside the related page.

Managing TCP Open Port Scanner in Security Settings

1. Navigate to the "Security" tab in the top menu.
2. Under "Security Status" on the left panel, select "TCP Open Port Scanner." Ensure it is marked as enabled.
3. Check the main panel, which shows the status of the scanner, labeled as "Enabled," with the date and time of the last check.
4. In the "Open Ports Found" section, verify that no new open ports are found, indicated by the message “No new Open Ports found.”
5. Review "Ports marked as safe." For instance, port 7001 is listed, with detection dates displayed.
6. Use the "Remove all" button to clear ports marked as safe if needed.

A discovered opened port is a potential threat to the network, especially if combined to a default password of the device reached through that port.

The discovered opened ports which are identified by Domotz can be marked as safe or removed in case they have been closed:

- Safe: a discovered opened port which is marked as "Safe" is recognized by the Domotz User as required on that network, and it will not be reported as a threat on the higher level dashboard. They will not reappear in the list of discovered opened ports. The Domotz user acknowledges that the port is opened and it is safe to be so.
- Removed: on the other hand, if the user removes one discovered opened port, it means that the user has resolved the potential threat (e.g. closing the port on the WAN side of the gateway, removed the Port Forwarding, etc). In this case, if the Domotz Cloud will discover again the same port as open in a subsequent scan, the port will be reported again as a potential threat.

**Note**: This type of Perimeter Security scan is performed from the cloud toward the WAN side of the network. It only identifies if specific TCP ports are open and if so, they are reported. However, it is not possible for Domotz to understand which internal device is exposed behind a specific TCP port.

## Security Status - UPnP**Port Forwarding Scanner (LAN side)**

When enabled, Domotz performs periodical UPnP Port Forwarding scans from the Domotz Agent against the primary gateway device (to check whether the UPnP Port Forwarding mechanism is enabled). Moreover, the Domotz Agent will also monitor for any device internal to the network which is trying to leverage the UPnP capabilities of the Gateway to open ports and enable port forwarding to it.

**Note**: For security purposes, UPnP Port Forwarding is recommended to be disabled on every gateway of the network, especially on the ones bridging with the WAN side of the network.

When enabled, Domotz performs periodical scans against the Gateway and monitors all the devices within the network.

The automatic UPnP Port Forwarding Scanner can be enabled inside the related page.

UPnP Security Issues Overview

1. Navigate to the "Security" tab at the top of the interface.
2. In the left sidebar, under "Security Status," select "UPnP Port Forwarding Scanner."
3. The main panel will display "7 UPnP Issues Found," indicating that the UPnP Port Forwarding service is enabled, which could be a security risk.
4. A toggle switch shows whether the scanner is enabled or disabled.
5. Below, the "Latest Issues" section lists devices with open ports:
   - "AV Router" with public port 22178 detected on July 24, 2026.
   - Several "Rack Service PC" entries showing different public ports such as 13239, 32375, and 24721, with a common local port of 7070 and description "AnyDesk."
6. Each entry has a "Last Detected" timestamp detailing when the issue was found.
7. Options are available to "Mark all UPnP Issues as Safe" or "Remove all" found issues.

The gateways which are identified by Domotz with UPnP Port Forwarding enabled, and the devices trying to leverage this capability can be marked as safe or removed in case they have been resolved:

- Safe: a discovered UPnP Port Forwarding device (either the Gateway itself or all the devices attempting to leverage this capability) is marked as "Safe" is recognized by the Domotz User as required on that network, and it will not be reported as a threat on the higher level dashboard. They will not re-appear in the list of discovered opened ports. The Domotz user acknowledges that the UPnP Port Forwarding is required it is safe to be so.
- Removed: on the other hand, if the user removes one discovered UPnP Port Forwarding possible threat, it means that the user has resolved it (e.g. disabling UPnP Port Forwarding on the gateway, identified devices removed, etc). In this case, if the Domotz Agent will discover again the UPnP Port Forwarding as enabled (or device attempting to leverage it) in a subsequent scan, the same will be reported again as a potential threat.

## Security Issues Alerts

From inside the Security tab, in the Alerts sub-tab, the user can enable which type of Alert he wants to receive in case of any potential security threat discovered on the network:

Viewing Security Status and Alerts in a Software Dashboard

1. Navigate to the top menu and select the "Security" tab.
2. On the left sidebar, locate "Security Status" under which you'll find options like "TCP Open Port Scanner" and "UPnP Port Forwarding Scanner," both marked as "Enabled."
3. View "Security Alerts" in the main pane. The "Network Events" section shows alerts like "New Device Discovery" and "TCP Open Port and UPNP Port Forwarding," each indicating security issues.
4. Alerts can be configured for notifications via mobile or email by selecting the corresponding icons.

**Note**: The above Alerts refer to the personal account (email and push Notification contact channels only). If the user is willing to receive notifications for Security Perimeter scans on different channels, the user should leverage the Shared Alert profiles. Please refer to [Shared Alerts, Webhooks and Ticketing Systems.](https://help.domotz.com/user-guide/shared-alerts-webhooks-ticketing-systems/)

If you need any further information regarding the topics discussed above, please feel free to contact us at support@domotz.com.
