Skip navigation

This is an archived version of the document. The current version can be viewed here.

Currently Being Moderated

How do I exclude hosts and/or ports from being scanned?

Created by kb-author-1 on May 17, 2010 5:43 PM - Last modified by kb-author-1 on Jul 15, 2010 1:12 PM


Issue:

How do I exclude ports and/or hosts from being scanned so that scans do not trigger alerts from IDS systems?

 

 

 

Cause:

QualysGuard scans set off Intrusion Detection/Prevention Systems when scanning certain ports on certain hosts. The Intrusion Detection/Prevention System detects the QualysGuard scan as malicious traffic and sets off alerts.

 

 


Solution:

The ideal solution is to whitelist the QualysGuard scanner in the IDS/IPS.  If this is not possible, the procedures below to exclude certain hosts or ports from being scanned.

 

 

 

To exclude entire hosts:

 

-Navigate to Setup > Excluded Hosts.

 

-Enter the desired IP addresses.

 

-Click Save.

 

 

 

All hosts in this list will be excluded from future maps or scans.

 

 

 

To exclude certain ports:

 

-Navigate to Tools > Option Profiles.

 

-Click New > Option Profile.

 

-Enter a title for the new profile and select any desired options under the Scan and Map tabs.

 

-Select the Additional tab and click on the Advanced button.

 

-Click Blocked Resources to activate this feature.

 

-Select Custom Port List.

 

-Enter the ports not to be scanned.

 

-To apply these settings to all IP addresses in your account, select All registered IPs. To apply it only to certain hosts, select Custom IP list and enter the specific hosts that are not to be scanned on the specified ports.

 

-Click Save to save the new profile.

 

-Launch a scan with the new profile you created.

 

 

 

 

Qualys   Support KnowledgeBase

http://community.qualys.com/community/kb

 

 

 

ID:  0001.007.613.000

Comments (0)