Manuals
/
IBM Partner Pavilion
/
Computer Equipment
/
Network Router
IBM Partner Pavilion
2.3
manual
Part 4. Appendixes
Models:
2.3
1
171
187
187
Download
187 pages
31.13 Kb
168
169
170
171
172
173
174
175
Install
Default
Inheritance indicators
Maintenance
Section B Policy configuration
Access level
Command Impact
Battery return program
Procedure
Types of backups
Page 171
Image 171
Part 4. Appendixes
© Copyright IBM Corp. 1997, 2009
163
Page 170
Page 172
Page 171
Image 171
Page 170
Page 172
Contents
User Guide Version
Copyright statement
Trademarks and Disclaimer
Iv Enterprise Scanner User Guide
Contents
Part 4. Appendixes 163
Part 3. Maintenance
About this book
Audience
Topics
Technical support contacts
Related publications
Chapters
Part 1. Scanning from the Proventia Manager
Enterprise Scanner User Guide
Section a Network configuration
Section B Policy configuration
Ad hoc scanning in the Proventia Manager
About this task
Section a Network configuration
Configuring the management network interface
Procedure
Maximum assets per assessment subtask
Configuring the scanning network interface
Option Description Interface
Maximum IPs per discovery subtask
Configuring scanning interface DNS settings
Destination Network
Configuring routes for perspective
Assigning perspective to a scanning interface
Option Description Perspective
Option Metric Description
Section B Policy configuration
Defining assets for a discovery scan
Before you begin
Create groupings interactively
Displaying assessment checks by groups
If you want to Then Clear groupings
Click Clear Groupings
Displaying information about assessment checks
Selecting assessment checks with filters
Option Description Ports to scan with generic TCP checks
Click the Common Settings tab
Option Description Discover and report TCP services
Discover and report UDP services
Obtained information is older than
Default
Option Description Ports to scan with generic UDP checks
Option Description Dynamically determine OS if previously
Access level
Option Description Verify account access level before using
Local group membership to verify access
Access domain controllers to verify access
Maximum Allowable Lockout Duration
Lockout Allowed is enabled. When
Option Description Allowed account lockout
Temporary lockout allowed Enterprise
Defining assessment credentials for a policy
Account Level
Option Description Account Type SSH Local
Account Type SSH Domain
Domain/Host
Defining the service names associated with TCP and UDP ports
Excluded Hosts box
Defining ports or assets to exclude from a scan
If you want to Then Exclude ports
Exclude assets
Scan policy Required
Interpreting scan results in the Proventia Manager
Running an ad hoc scan
Action Icon Description
Monitoring the status of a scan
Viewing the results of an ad hoc scan
Exporting scan results from Proventia Manager
Click View/Manage Log Files
Field Description
Purging scan data from the database
Enterprise Scanner User Guide
Part 2. Scanning from the SiteProtector Console
Enterprise Scanner User Guide
Enterprise Scanner policies
General inheritance behavior
Inheritance indicators
Initially blank or unconfigured?
Policy inheritance with Enterprise Scanner policies
Enterprise Scanner policies
About this task
Select Network Enterprise Scanner from the Agent Type list
Viewing asset or agent policies for Enterprise Scanner
Important Do not click Open
Policy inheritance with agent policies
Contents of an agent policy
Agent policies for Enterprise Scanner
Agent policy descriptions for Enterprise Scanner
Network Locations policy
Assigning perspective to a scanning interface
Configuring routes for perspective
Event notification settings for Enterprise Scanner
Notification policy
Click the Event Notification tab
Account Purpose
Access policy
Configuring advanced parameters for event notification
Click the Advanced Parameters tab
Networking policy
Configuring the management network interface
Configuring the scanning network interface
Configuring scanning interface DNS settings
Services policy
Network Time Protocol section
Enable the network time protocol NTP
Time policy
If you want to Then Change the date and time for the agent
Update Settings policy
Asset policies for Enterprise Scanner
Asset policy descriptions for Enterprise Scanner
Policy contents
Discovery policy
Scope
Before you begin
Defining assets to discover
Displaying information about assessment checks
Assessment policy
Displaying assessment checks by groups
Selecting assessment checks with filters
Configuring common assessment settings
Information is older than
Option Description Dynamically determine OS if SiteProtector
Try to confirm the access level
Option Description Allowed account lockout
Defining assessment credentials for a policy
Assessment Credentials policy
Option Description Account Type Windows
Scan Control policy
Current cycle start date
Option Description Job name
Cycle start date
Cycle duration
Important consideration for multiple agents
Scan Window policy
Defining when scanning is allowed
Defining ports or assets to exclude from a scan
Scan Exclusion policy
Policy inheritance
Network Services policy
Default settings
Service definition
Configuring a Network Services policy
Configuration options
Ad Hoc Scan Control policy
Running an ad hoc discovery scan with Enterprise Scanner
Running an ad hoc assessment scan with Enterprise Scanner
Click Generate Support Data File
Click the Debug Settings tab
Understanding scanning processes in SiteProtector
What is perspective?
Perspectives in policies
Policy How to use Applies to
Defining perspectives
Placing agents in the correct perspective
Network locations and perspectives
Term Description
Scan jobs and related terms
Definitions
Assets with unassigned criticality
Common management tasks
Types of tasks
Scheduled and running scans
Importance of tasks and subtasks
Scan type Number of tasks
Priorities for running tasks
Tasks per type of scan
Criticality and assessment tasks
Type of scan Reason for prioritization
Stages of a scanning process
Task prioritization
Dynamic prioritization
Stage Description
Process for a scanning cycle
Assessment cycle duration
Size of scan windows
Calibration considerations
Discovery cycle duration
Achieving the right balance
Enterprise Scanner User Guide
Background scanning in SiteProtector
Determining when background scans run
Type of scan Description
How policies apply to ad hoc and background scans
Asset policies and ad hoc scans
Changing assessment and discovery policies
Scan window and refresh cycle examples
Scan Control policy
Background scanning checklists for Enterprise Scanner
Checklist for background discovery scanning
Checklist for background assessment scanning
Enabling background scanning
Option Description Next cycle start date
Defining when scanning is allowed
Procedure
Type a series of individual IP addresses, a
Defining network services
Defining assessment credentials for a policy
Option Description Account Type SSH Local
Monitoring scans in SiteProtector
Viewing discovery job results
Viewing your scan jobs
On ScanGroupName for hosts with
Viewing assessment job results
Assessment subtask explanation
This part of the description Describes Finished Assessment
Enterprise Scanner User Guide
Managing scans in SiteProtector
Impact of restarting scan jobs
Command Impact
Stopping and restarting scan jobs
Impact of stopping scan jobs
Suspending and enabling all background scans
Type of scan Steps to initiate
Registration and authentication
Minimum scanning requirements
Steps to initiate a scan
Priority
Troubleshooting scanning behaviors for ad hoc scans
Scanning behaviors for ad hoc scans
Inheritance
Expected scanning behaviors for background scans
Managing scans in SiteProtector
Enterprise Scanner User Guide
Interpreting scan results in SiteProtector
Certainty of Osid sources
OS identification Osid certainty
What determines certainty?
Sources of Osid
Rules for updating Osid
How Osid is updated in Enterprise Scanner
Conditions for reassessing Osid
Exception
Portal Description
Setting up a Summary view for vulnerability management
Summary page for vulnerability management
Vulnerability management options
Portal Description
Benefits
Viewing vulnerabilities by asset in Enterprise Scanner
About vulnerability assessment
Creating custom views
Field descriptions
Field Description
Viewing vulnerabilities by detail in Enterprise Scanner
Field Description
Viewing vulnerabilities by object in Enterprise Scanner
Field
Vulnerability view by vulnerability name
Field Description
Report Description
Running reports in the SiteProtector Console
Types of assessment reports
Report descriptions
Report Description
Procedure
Enterprise Scanner User Guide
Logs and alerts
Log size
Log files and alert notification
Two types of log files
Two types of information
System log descriptions
System logs
Statistic Description
Getting log status information
Enterprise Scanner ES logs
Log descriptions
Changing logging detail
Delete
Downloading Enterprise Scanner ES log files
Download
Delete a log file Click View/Manage Log Files
Icon Description
Alerts log
Risk level icons
Event information icons
Downloading and saving an Alerts log
Click Generate new log file from Alerts
File Description
Clearing the Alerts log
Finding specific events in the Alerts log
Click Clear current Alerts from event log
Enterprise Scanner User Guide
If you want to Then Search the Alert log file by Alert ID
Number
Search by Alert Id# box
Enterprise Scanner User Guide
Ticketing and remediation
Custom categories
Ticketing and Enterprise Scanner
Tickets
Vulnerability auto ticketing
Scanning recommendations
Remediation process overview for Enterprise Scanner
Task overview
Remediation tasks for Enterprise Scanner
Option Tab Description
Task 6 Close the ticket
Part 3. Maintenance
Enterprise Scanner User Guide
Performing routine maintenance
Shutting down your Enterprise Scanner
Removing an agent from SiteProtector
Options for backing up Enterprise Scanner
Types of backups
If you restore a system before you make backups
Date of last system backup
Backing up configuration settings
Click the Full Backup tab Choose an option
Making full system backups
Updating Enterprise Scanner
Update location Description
Types of updates
Update locations
Type of update Content
Updating options
Update options
Installation options with scheduled updates
Rollbacks and backups
Authentication method Advantages and Disadvantages
Configuring explicit-trust authentication with an XPU server
Name
Configuring an Alternate Update location
Select the Use Alternate Update Server check box
Option Description Host or IP
CA Certificate
Option Description Trust Level
Configuring an Http Proxy
Configuring notification options for XPUs
Select Enable Proxy
Option Description Check for updates daily or weekly
Scheduling a one-time firmware update
Configuring automatic updates
Click the Update Settings tab
Delayed
Option Description Check for updates at given intervals
Option Description Do Not Install
Automatically Install Updates
Manually installing updates
Viewing the status of the Enterprise Scanner agent
Model
Proventia Manager Home
System status
Network interface status
Updates status
Protection status
Header
Viewing agent status
Viewing agent status in the SiteProtector Console
Troubleshooting the Enterprise Scanner sensor
Module or process Description Troubleshooting option
Viewing the status of the CAM modules
Module or process Description Troubleshooting option
Part 4. Appendixes
Enterprise Scanner User Guide
165
Enterprise Scanner User Guide
Product handling information
World trade safety information
Product safety labels
Laser safety information
Laser compliance
Product recycling and disposal
Battery return program
For the European Union
For Taiwan
Electronic emissions notices
For California
Federal Communications Commission FCC Statement
Canadian Department of Communications Compliance Statement
European Union EU Electromagnetic Compatibility Directive
EC Declaration of Conformity In German
Japan Class a Compliance Statement
People’s Republic of China Class a Compliance Statement
Korean Class a Compliance Statement
Enterprise Scanner User Guide
177
Index
Reassessing 105 Rules Sources
Scan job
Top
Page
Image
Contents