How does the communication with the Scanner Appliance work?
This article describes how the scanner appliance communicates with the platform, and how communication is secured in both cloud and on-prem installations.
Cloud & on-prem installations
The scanner appliance communicates the same way in both types of installation. The only difference is where it connects:
- Cloud
The scanner appliance connects to the Holm Security cloud platform. - On-prem
The scanner appliance connects to your on-prem core machine instead of the Holm Security public environment.
In this article, "the platform" means the cloud platform or the core machine, depending on your installation.
How the scanner appliance communicates
The scanner appliance connects to the platform over HTTPS. It uses this connection to:
- Send information about its status.
- Download updates.
- Send and receive scan data and scan settings.
All communication between the platform and the scanner appliance goes through this HTTPS tunnel.
The scanner appliance also sets up a reverse SSH tunnel to the platform. This tunnel is used to send commands to the scanner appliance.
A valid SSL certificate is required
The SSL certificate must be valid. If it is not, the scanner appliance will not receive any data.
How communication is secured
- Encrypted connection
All data and settings are sent through the HTTPS tunnel. - Unique authentication token
Each scanner appliance has its own token that it uses to authenticate to the platform. - Signed updates
Every update the scanner appliance downloads and installs must be signed with our public key. - SSH key authentication
The reverse SSH tunnel uses SSH key authentication
Data storage
The scanner appliance stores scan data locally and sends it to the platform, where it is shown in Security Center.