Network Services policy

Use the Network Services policy on the SiteProtector Console to define service names associated with TCP and UDP ports.

You can modify some properties of a default service in the policy, and you can add your own customized services to the policy.

Scope

The Network Services policy applies to assessment scans that run as either background or ad hoc scans.

Default settings

The IBM ISS X-Force defines the default Network Services policy and might update the policy in an X-Press Update (XPU). The default policy applies to all groups that do not override it. The service names defined in the policy are referenced as target types in Enterprise Scanner check definitions. X-Force adds a service name when a new check uses a service that was not previously defined in the policy.

Policy inheritance

A Network Services policy defined in association with a group overrides the default definitions only for those services explicitly referenced in the user-defined policy. A user-defined Network Services policy includes only explicit overrides of inherited service definitions, which ensures that all groups automatically inherit XPU updates to the default Network Services policy.

Service definition

The network services policy includes the following information about each service:

vService name

vService description

vPort number

vProtocol (TCP or UDP)

vWhether some (or all) instances of the service operate over SSL on this port within your network

vWhether to include the port in the service scan

vWhether you have customized a default service or created a custom service

62Enterprise Scanner: User Guide

Page 70
Image 70
IBM Partner Pavilion 2.3 manual Network Services policy, Default settings, Policy inheritance, Service definition