Policy scanning

How do I create a policy scan profile?

To be able to run a policy scan, you need to set up a policy scanning profile, and this needs to be an authenticated profile; here is how you do it:

  1. Log in to the Security Center.
  2. Click on Scan Profiles.
  3. Click on +Create scan profile > Policy profile.
  4. Under the headline General settings, enter the following:
    • Name: the name of the Scan profile.
    • Owner: the owner of the report.
  5. Under the headline Policy, choose your desired template.
  6. Under the headline Authentication, you can add a new authentication record or choose an existing one for Windows and Linux/Unix. Notice that you can only have one authentication record per profile and operating system. See the instructions below.

Linux/Unix authentication record

  1. Set the Authentication information by clicking the drop-down and selecting New.
  2. Select a Name for your Authentication Record
  3. Add the Port to be used for authentication if you have a specific port. Otherwise, the standard port 22 will be used.
  4. Type the Username to be used for the authentication.
  5. Choose the method of authentication: SSH Key or Password.
  6. Add the information based on the choice you made.
  7. Done!

Linux Authentication Method
For the password option, we require password authentication to be turned on for the SSH service.
For the SSH Key option, we require an SSH-authorized RSA private key.

Windows authentication record

  1. Set the Authentication information by clicking the drop-down and selecting New.
  2. Select a Name for your Authentication Record
  3. Type in the credentials you would like to use for your authenticated scan.
    1. Username
    2. Password
    3. Domain
  4. Choose which NTLM protocol (NTLM v2, NTLM v1, or NTLM v2 Only) to use based on your network configuration.
  5. Done!  

Authenticated scanning

Read this for more information regarding authenticated network scans:
What is an authenticated scan?