Get Started
Best Practices for internal scanning
9
Best Practices for internal scanning
Here are our best practices related to internal scanning.
Avoid scanning through a firewall from the inside out
Problems can arise when scan traffic is routed through the firewall from the inside out, i.e.
when the scanner Appliance is sitting in the protected network area and scans a target
which is located on the other side of the firewall. We recommend placing scanner
Appliances in your network topology in a way that scanning and mapping through a
firewall from the inside out is avoided if possible.
VLAN Support
VLAN configuration options: 1) If you have connected the
LAN interface to a 802.1q trunked port and need your
Scanner Appliance to use VLAN tags on the LAN default
network, enter the VLAN tag number using the Appliance
console. 2) For any Appliance, you can choose option 1)
and also configure more VLANs (to be used for scanning)
using the Qualys user interface.
DHCP or Static IP
By default the Scanner Appliance is pre-configured with
DHCP. If configured with a static IP address, be sure you
have the IP address, netmask, default gateway, primary
DNS and WINS server (if appropriate).
Proxy Support
The Scanner Appliance includes Proxy support with or
without authentication — Basic or NTLM. Proxy-level
termination (as implemented in SSL bridging, for example)
is not supported. SOCKS proxies are not supported.
WINS Support
If your network is running Windows Internet Naming
Service (WINS), the Scanner Appliance needs to use it for
host name resolution during scanning. For an Appliance
configured with DHCP, please be sure your WINS server IPs
(primary and secondary) are added to your DHCP subnet
configuration using “option netbios-name-servers WINS1,
WINS2;”. For an Appliance with a static IP address, the
WINS servers are defined with the static IP settings using
the Appliance console.
Network Time Protocol (NTP)
The Scanner Appliance syncs the time from the Qualys
SOC (Security Operations Center) for your
account/location automatically. For this reason, there is
nothing you need to configure for NTP.
Learn more
Summary of Contents for QGSA-5120-A1
Page 1: ...Scanner Appliance User Guide December 20 2021 ...
Page 6: ...Preface 6 ...
Page 58: ...Troubleshooting Where can I find the model number and serial number 58 ...
Page 60: ...Appendix A Product Specifications 60 ...
Page 62: ...Appendix B Software Credits 62 ...
Page 64: ...Appendix C Safety Notices 64 ...