How do I create a policy scan profile?
To be able to run a policy scan, you need to set up a policy scanning profile, and this needs to be an authenticated profile; here is how you do it:
- Log in to Security Center.
- In the main navigation bar, hover over Assessments.
- From the dropdown menu that appears, select Profiles.
- Click on Create scan profile > Policy profile.
- Under the headline General settings, enter the following:
- Name: the name of the scan profile.
- Owner: the owner of the report.
- Under the headline Policy, choose your desired template.
- Under the headline Authentication, you can add a new authentication record or choose an existing one for Windows and Linux/Unix. Notice that you can only have one authentication record per profile and operating system. See the instructions below.
Linux/Unix authentication record
- Set the Authentication information by clicking the drop-down and selecting New.
- Select a Name for your authentication record.
- Add the Port to be used for authentication if you have a specific port. Otherwise, the standard port 22 will be used.
- Type the Username to be used for the authentication.
- Choose the method of authentication: SSH Key or Password.
- Add the information based on the choice you made.
- Done!
Linux authentication method
For the password option, we require password authentication to be turned on for the SSH service.
For the SSH Key option, we require an SSH-authorized RSA private key.
Windows authentication record
- Set the Authentication information by clicking the drop-down and selecting New.
- Select a Name for your authentication record.
- Type in the credentials you would like to use for your authenticated scan.
- Username
- Password
- Domain
- Enable Authenticate over HTTPS if you want to run scans over HTTPS.
- Choose which NTLM protocol (NTLM v2, NTLM v1, or NTLM v2 Only) to use based on your network configuration.
- Done!
Authenticated scanning
Read this for more information regarding authenticated network scans:
What is an authenticated scan?
Read this for more information regarding the requirements for policy network scans:
What are the requirements for Policy scanning?