Manuals
/
IBM Partner Pavilion
/
Computer Equipment
/
Network Router
IBM Partner Pavilion
2.3
manual
User Guide Version
Models:
2.3
1
1
187
187
Download
187 pages
31.13 Kb
1
2
3
4
5
6
7
8
Install
Default
Inheritance indicators
Maintenance
Section B Policy configuration
Access level
Command Impact
Battery return program
Procedure
Types of backups
Page 1
Image 1
IBM Proventia Network Enterprise Scanner
User Guide
Version 2.3
Page 1
Page 2
Page 1
Image 1
Page 1
Page 2
Contents
User Guide Version
Copyright statement
Trademarks and Disclaimer
Iv Enterprise Scanner User Guide
Contents
Part 4. Appendixes 163
Part 3. Maintenance
Audience
About this book
Topics
Technical support contacts
Related publications
Chapters
Part 1. Scanning from the Proventia Manager
Enterprise Scanner User Guide
Section B Policy configuration
Section a Network configuration
Ad hoc scanning in the Proventia Manager
Configuring the management network interface
Section a Network configuration
Procedure
About this task
Option Description Interface
Configuring the scanning network interface
Maximum IPs per discovery subtask
Maximum assets per assessment subtask
Configuring scanning interface DNS settings
Assigning perspective to a scanning interface
Configuring routes for perspective
Option Description Perspective
Destination Network
Defining assets for a discovery scan
Section B Policy configuration
Before you begin
Option Metric Description
If you want to Then Clear groupings
Displaying assessment checks by groups
Click Clear Groupings
Create groupings interactively
Displaying information about assessment checks
Selecting assessment checks with filters
Option Description Discover and report TCP services
Click the Common Settings tab
Discover and report UDP services
Option Description Ports to scan with generic TCP checks
Option Description Ports to scan with generic UDP checks
Default
Option Description Dynamically determine OS if previously
Obtained information is older than
Local group membership to verify access
Option Description Verify account access level before using
Access domain controllers to verify access
Access level
Option Description Allowed account lockout
Lockout Allowed is enabled. When
Temporary lockout allowed Enterprise
Maximum Allowable Lockout Duration
Defining assessment credentials for a policy
Account Type SSH Domain
Option Description Account Type SSH Local
Domain/Host
Account Level
Defining the service names associated with TCP and UDP ports
If you want to Then Exclude ports
Defining ports or assets to exclude from a scan
Exclude assets
Excluded Hosts box
Scan policy Required
Interpreting scan results in the Proventia Manager
Running an ad hoc scan
Action Icon Description
Monitoring the status of a scan
Exporting scan results from Proventia Manager
Viewing the results of an ad hoc scan
Click View/Manage Log Files
Field Description
Purging scan data from the database
Enterprise Scanner User Guide
Part 2. Scanning from the SiteProtector Console
Enterprise Scanner User Guide
Enterprise Scanner policies
Initially blank or unconfigured?
Inheritance indicators
Policy inheritance with Enterprise Scanner policies
General inheritance behavior
Enterprise Scanner policies
About this task
Select Network Enterprise Scanner from the Agent Type list
Viewing asset or agent policies for Enterprise Scanner
Important Do not click Open
Agent policies for Enterprise Scanner
Contents of an agent policy
Agent policy descriptions for Enterprise Scanner
Policy inheritance with agent policies
Network Locations policy
Assigning perspective to a scanning interface
Configuring routes for perspective
Notification policy
Event notification settings for Enterprise Scanner
Click the Event Notification tab
Configuring advanced parameters for event notification
Access policy
Click the Advanced Parameters tab
Account Purpose
Networking policy
Configuring the management network interface
Configuring the scanning network interface
Configuring scanning interface DNS settings
Services policy
Time policy
Enable the network time protocol NTP
If you want to Then Change the date and time for the agent
Network Time Protocol section
Asset policies for Enterprise Scanner
Update Settings policy
Asset policy descriptions for Enterprise Scanner
Discovery policy
Policy contents
Scope
Before you begin
Defining assets to discover
Displaying information about assessment checks
Assessment policy
Displaying assessment checks by groups
Selecting assessment checks with filters
Configuring common assessment settings
Information is older than
Option Description Dynamically determine OS if SiteProtector
Try to confirm the access level
Option Description Allowed account lockout
Defining assessment credentials for a policy
Assessment Credentials policy
Option Description Account Type Windows
Scan Control policy
Cycle start date
Option Description Job name
Cycle duration
Current cycle start date
Important consideration for multiple agents
Scan Window policy
Defining when scanning is allowed
Defining ports or assets to exclude from a scan
Scan Exclusion policy
Default settings
Network Services policy
Service definition
Policy inheritance
Configuring a Network Services policy
Ad Hoc Scan Control policy
Configuration options
Running an ad hoc discovery scan with Enterprise Scanner
Running an ad hoc assessment scan with Enterprise Scanner
Click Generate Support Data File
Click the Debug Settings tab
Understanding scanning processes in SiteProtector
What is perspective?
Defining perspectives
Policy How to use Applies to
Placing agents in the correct perspective
Perspectives in policies
Network locations and perspectives
Definitions
Scan jobs and related terms
Assets with unassigned criticality
Term Description
Scheduled and running scans
Types of tasks
Importance of tasks and subtasks
Common management tasks
Tasks per type of scan
Priorities for running tasks
Criticality and assessment tasks
Scan type Number of tasks
Task prioritization
Stages of a scanning process
Dynamic prioritization
Type of scan Reason for prioritization
Stage Description
Process for a scanning cycle
Calibration considerations
Size of scan windows
Discovery cycle duration
Assessment cycle duration
Achieving the right balance
Enterprise Scanner User Guide
Background scanning in SiteProtector
Determining when background scans run
Asset policies and ad hoc scans
How policies apply to ad hoc and background scans
Changing assessment and discovery policies
Type of scan Description
Scan window and refresh cycle examples
Scan Control policy
Checklist for background discovery scanning
Background scanning checklists for Enterprise Scanner
Checklist for background assessment scanning
Enabling background scanning
Option Description Next cycle start date
Defining when scanning is allowed
Procedure
Type a series of individual IP addresses, a
Defining network services
Defining assessment credentials for a policy
Option Description Account Type SSH Local
Monitoring scans in SiteProtector
Viewing discovery job results
Viewing your scan jobs
Assessment subtask explanation
Viewing assessment job results
This part of the description Describes Finished Assessment
On ScanGroupName for hosts with
Enterprise Scanner User Guide
Managing scans in SiteProtector
Stopping and restarting scan jobs
Command Impact
Impact of stopping scan jobs
Impact of restarting scan jobs
Suspending and enabling all background scans
Minimum scanning requirements
Registration and authentication
Steps to initiate a scan
Type of scan Steps to initiate
Scanning behaviors for ad hoc scans
Troubleshooting scanning behaviors for ad hoc scans
Inheritance
Priority
Expected scanning behaviors for background scans
Managing scans in SiteProtector
Enterprise Scanner User Guide
Interpreting scan results in SiteProtector
What determines certainty?
OS identification Osid certainty
Sources of Osid
Certainty of Osid sources
Conditions for reassessing Osid
How Osid is updated in Enterprise Scanner
Exception
Rules for updating Osid
Summary page for vulnerability management
Setting up a Summary view for vulnerability management
Vulnerability management options
Portal Description
Portal Description
About vulnerability assessment
Viewing vulnerabilities by asset in Enterprise Scanner
Creating custom views
Benefits
Field descriptions
Field Description
Viewing vulnerabilities by detail in Enterprise Scanner
Field Description
Viewing vulnerabilities by object in Enterprise Scanner
Field
Vulnerability view by vulnerability name
Field Description
Types of assessment reports
Running reports in the SiteProtector Console
Report descriptions
Report Description
Report Description
Procedure
Enterprise Scanner User Guide
Logs and alerts
Two types of log files
Log files and alert notification
Two types of information
Log size
System log descriptions
System logs
Enterprise Scanner ES logs
Getting log status information
Log descriptions
Statistic Description
Changing logging detail
Download
Downloading Enterprise Scanner ES log files
Delete a log file Click View/Manage Log Files
Delete
Risk level icons
Alerts log
Event information icons
Icon Description
Click Generate new log file from Alerts
Downloading and saving an Alerts log
File Description
Finding specific events in the Alerts log
Clearing the Alerts log
Click Clear current Alerts from event log
Enterprise Scanner User Guide
Number
If you want to Then Search the Alert log file by Alert ID
Search by Alert Id# box
Enterprise Scanner User Guide
Ticketing and remediation
Tickets
Ticketing and Enterprise Scanner
Vulnerability auto ticketing
Custom categories
Scanning recommendations
Remediation process overview for Enterprise Scanner
Task overview
Remediation tasks for Enterprise Scanner
Option Tab Description
Task 6 Close the ticket
Part 3. Maintenance
Enterprise Scanner User Guide
Performing routine maintenance
Shutting down your Enterprise Scanner
Removing an agent from SiteProtector
If you restore a system before you make backups
Types of backups
Date of last system backup
Options for backing up Enterprise Scanner
Backing up configuration settings
Click the Full Backup tab Choose an option
Making full system backups
Updating Enterprise Scanner
Update locations
Types of updates
Type of update Content
Update location Description
Installation options with scheduled updates
Update options
Rollbacks and backups
Updating options
Authentication method Advantages and Disadvantages
Configuring explicit-trust authentication with an XPU server
Select the Use Alternate Update Server check box
Configuring an Alternate Update location
Option Description Host or IP
Name
CA Certificate
Option Description Trust Level
Configuring notification options for XPUs
Configuring an Http Proxy
Select Enable Proxy
Configuring automatic updates
Scheduling a one-time firmware update
Click the Update Settings tab
Option Description Check for updates daily or weekly
Option Description Do Not Install
Option Description Check for updates at given intervals
Automatically Install Updates
Delayed
Manually installing updates
Viewing the status of the Enterprise Scanner agent
System status
Proventia Manager Home
Network interface status
Model
Protection status
Updates status
Header
Viewing agent status
Viewing agent status in the SiteProtector Console
Module or process Description Troubleshooting option
Troubleshooting the Enterprise Scanner sensor
Viewing the status of the CAM modules
Module or process Description Troubleshooting option
Part 4. Appendixes
Enterprise Scanner User Guide
165
Enterprise Scanner User Guide
Product handling information
World trade safety information
Product safety labels
Laser compliance
Laser safety information
Product recycling and disposal
Battery return program
For the European Union
For Taiwan
For California
Electronic emissions notices
Federal Communications Commission FCC Statement
European Union EU Electromagnetic Compatibility Directive
Canadian Department of Communications Compliance Statement
EC Declaration of Conformity In German
Japan Class a Compliance Statement
People’s Republic of China Class a Compliance Statement
Korean Class a Compliance Statement
Enterprise Scanner User Guide
177
Index
Reassessing 105 Rules Sources
Scan job
Top
Page
Image
Contents