C:\ARDI\NOTES> type network-mapping.txt
How I mapped a bank office network in five stages
Cara saya memetakan jaringan kantor bank dalam lima tahap
I needed a complete, reproducible map of the office network: IP plan, routing, VLANs, every switch and endpoint. Here is the method I used to build it without breaking anything in a regulated environment.
Saya butuh peta jaringan kantor yang lengkap dan bisa diulang: rencana IP, routing, VLAN, setiap switch dan perangkat. Ini metode yang saya pakai untuk membuatnya tanpa merusak apa pun di lingkungan yang diawasi regulator.
00 Before any scan: write down the scopeSebelum scan apa pun: tulis cakupannya
Banks get audited. Before running a single active scan I wrote down the date, who authorised it, which subnets were in scope and which devices were excluded, and kept an exclusion list that every scan had to respect. Raw output stays in the project folder and is never shared, because it contains addresses and hostnames.
Bank pasti diaudit. Sebelum menjalankan satu scan aktif pun, saya mencatat tanggal, siapa yang memberi izin, subnet mana yang masuk cakupan dan perangkat mana yang dikecualikan, serta membuat daftar pengecualian yang wajib dipatuhi setiap scan. Hasil mentah disimpan di folder proyek dan tidak pernah dibagikan, karena berisi alamat dan nama host.
01 Local reconRecon lokal
Start from the PC you are sitting at, with Windows built-ins only: ipconfig /all, route print, arp -a. This tells you your own subnet, the gateway and the neighbours you have already talked to, without sending anything unusual onto the network.
Mulai dari PC yang sedang dipakai, hanya dengan perintah bawaan Windows: ipconfig /all, route print, arp -a. Ini memberi tahu subnet sendiri, gateway, dan perangkat tetangga yang sudah pernah berkomunikasi, tanpa mengirim apa pun yang aneh ke jaringan.
02 Passive listeningMendengarkan pasif
Run Wireshark or tshark and just listen: ARP, DHCP, broadcast and discovery traffic reveal devices, VLAN tags and services. Nothing is sent, so nothing can break.
Jalankan Wireshark atau tshark dan cukup dengarkan: lalu lintas ARP, DHCP, broadcast, dan discovery memperlihatkan perangkat, tag VLAN, dan layanan. Tidak ada yang dikirim, jadi tidak ada yang bisa rusak.
03 Active discovery, one VLAN at a timeDiscovery aktif, satu VLAN sekali jalan
Only now use Nmap, one subnet at a time, with the exclusion list and gentle timing. Ping sweeps first, then service detection only where needed.
Baru sekarang pakai Nmap, satu subnet sekali jalan, dengan daftar pengecualian dan timing yang pelan. Ping sweep dulu, lalu deteksi layanan hanya bila perlu.
04 Ask the switchesTanya ke switch
Where SNMP is available, walk the switches and routers for interfaces, MAC tables and neighbours. This is what turns a list of IP addresses into a real topology: which port each device is plugged into.
Kalau SNMP tersedia, telusuri switch dan router untuk interface, tabel MAC, dan perangkat tetangga. Inilah yang mengubah daftar alamat IP menjadi topologi sungguhan: perangkat mana tercolok di port mana.
05 Servers lastServer terakhir
The two dual-homed servers (core banking and file sharing) get their own careful look: which networks they sit on and what they route between.
Dua server dual-homed (core banking dan file sharing) diperiksa secara khusus: berada di jaringan mana saja dan apa yang dirutekan di antaranya.
→ From evidence to a diagramDari bukti ke diagram
- Everything is consolidated into structured YAML: hosts, VLANs, routes, DHCP and infrastructure. The inventory is the source of truth.
- The draw.io diagram is drawn from the inventory, not from memory.
- The last step is the useful one: a VLAN plan and recommendations written for management, not just a picture.
- Semua dikumpulkan ke dalam YAML terstruktur: host, VLAN, rute, DHCP, dan infrastruktur. Inventaris inilah sumber kebenarannya.
- Diagram draw.io digambar dari inventaris, bukan dari ingatan.
- Langkah terakhir yang paling berguna: rencana VLAN dan rekomendasi yang ditulis untuk manajemen, bukan sekadar gambar.
The order matters: quiet before loud, local before remote, and written permission before any of it.
Urutannya penting: yang senyap sebelum yang ramai, lokal sebelum jarak jauh, dan izin tertulis sebelum semuanya.
Need someone who documents the network before touching it?
Butuh orang yang mendokumentasikan jaringan sebelum menyentuhnya?
WhatsApp Email Download CVUnduh CV More projectsProyek lain