Defining Common Assessment Settings (Assessment Policy) - IBM Proventia Network Enterprise Scanner User Manual

Table of Contents

Advertisement

Chapter 7: Configuring Discovery and Assessment Policies

Defining Common Assessment Settings (Assessment Policy)

Introduction
Procedure
106
In addition to selecting the checks to run in an assessment scan, you can choose settings to
define additional scanning behavior in the Common Settings tab.
1. In the SiteProtector Console, set up a tab to display asset policies. (See page 74.)
2. On the navigation pane, select a group, and then open the Assessment policy for that
group.
3. Select the Common Settings tab.
4. Change any of the following settings as needed to define your security requirements:
Setting
Help HTML Prefix
Treatment of X-Force
Recommendations
Service Discovery
Assessment Port Ranges Ports to scan with generic TCP checks
Description
The location of the assessment check Help, specified as one of
the following:
the IBM ISS Web site that contains the up-to-date assessment
check documentation
the location of a locally stored version of the documentation.
Note: If you do not have access to the Internet and want to store
the assessment check Help documentation locally, see "Getting
Vulnerability Help for a SiteProtector Console without Internet
Access" in the SiteProtector Help for detailed instructions for
setting it up.
Enable each X-Force recommended check that is not
explicitly disabled in this policy
Does the following:
Enables each X-Force check that has not been customized by
changing one or more settings.
Determines whether or not new checks added in an XPU are
enabled by default.
Discover and report TCP services
Reports active TCP services for which the Service Scan flag is
enabled in the Network Services policy.
Discover and report UDP services
Reports active UDP services for which the Service Scan flag is
enabled in the Network Services policy.
The set of TCP ports to scan with generic TCP checks.
Note: A generic TCP check is one whose target type is tcp.
Ports to scan with generic UDP checks
The set of UDP ports to scan with generic UDP checks.
Note: A generic UDP check is one whose target type is udp.
Tip: Specify port ranges as follows:
Type a port or a range of ports.
Click Well Known to select a port from a list of well-known
ports.
Select the All check box to select all ports.
IBM Internet Security Systems

Advertisement

Table of Contents
loading

Table of Contents