Scan Exclusion policy
Use the Scan Exclusion policy on the SiteProtector Console to define specific ports
or assets to exclude from a scan of a group of assets.
Each Scan Exclusion policy defines the following information for the asset group
associated with the policy (and the groups that inherit from it):
vA list of ports against which no assessment checks will be run. (No checks run
against these ports on any host in the group. This applies to both TCP and UDP
ports.)
vA list of IP addresses not to scan.
Important: You should define the Scan Exclusion policy at a high level in your
group structure and allow the lower groups to inherit from it. If needed, you can
then override the policy at lower groups.
Scope
The Scan Exclusion policy applies to ad hoc and background assessment scans. It
does not apply to discovery scans.

Defining ports or assets to exclude from a scan

Use the Scan Exclusion policy on the SiteProtector Console to define specific ports
or assets to exclude from a scan of a group of assets.
Procedure
1. From the SiteProtector Console, create a tab to display asset policies.
2. In the navigation pane, select a group, and then open the Scan Exclusion policy
for that group.
3. Choose an option:
If you want to... Then...
Exclude ports Usea combination of typing the ports to
exclude and choosing the ports:
vType the ports to exclude, separated by
commas, in the Excluded Ports box.
vClick Well Known Ports, and then select
the ports to exclude.
Exclude assets Type the IP addresses(in dotted-decimal or
CIDR notation) of the hosts to exclude in the
Excluded Hosts box:
vType an IP address,and then press ENTER.
vType a range of IP addresses,and then
press ENTER.
Example: 172.1.1.100-172.1.1.200
vType a combination of both choices above,
and then press ENTER.
Note: A red box is displayed around the
Excluded Hosts box until the data is
validated.
Chapter3. Enterprise Scanner policies 61