How To Permit Campus Vulnerability Scanners Access To Your Systems
A knowledge base article about How To Permit Campus Vulnerability Scanners Access To Your Systems provided by the UC Berkeley IT Service Hub - Knowledge Portal
Below are the steps necessary to use the shared Address Group (ucbsec-vuln_scanners) that represents the campus vulnerability scanners managed by Information Security and Policy (ISP). Using this object to allow ISP to perform vulnerability scanning against your systems is heavily encouraged for all users. For vsys that are registered as containing restricted data and are in either the ewdc-high-security or campus-high-security device groups, allowing the vulnerability scanners is required by policy and is already enforced by an inherited rule in Panorama. As a result, users in these device groups do not need to add an allow rule as outlined below.
NOTE: if any of your systems contain restricted data and are not registered or are not in one of the high-security device groups, please contact security@berkeley.edu for help resolving this issue.
From the tabs at the top of the window choose “Policies”
Under “Security” in the left pane choose “Pre Rules”
Click “Add” from the bottom of the window. This should bring up a “Security Policy Rule” window.
In the “General” tab provide an appropriate name such as ‘Allow Vulnerability Scanners’ in the Name field
On the “Source” tab click the “Any” box above “Source Zone” and then click “Add” below the “Source Address” column.
In the drop down list that will appear for “Source Address” choose “ucbsec-vuln_scanners”
On the “Destination” tab select the appropriate Zone and Destinations. We recommend setting the Zone drop down box to ‘any’ and the “Destination Address” also as Any so that all of your systems can be scanned for vulnerabilities
On the “Actions” tab set the Profile Type to “None” so that the advanced security features will not block vulnerabilities scans and causing incorrect results
“Click “OK” to return to the list of all of your rules
Find the new rule ‘Allow Vulnerability Scanners’ (in this example) and click on it to highlight that rule.
At the bottom of the screen select “Move to Top” from the “Move” menu (If they are not at the top other blocking rules may supercede this policy and prevent it from being effective.)
From the “Commit” menu near the top of the screen chose “Commit to Panorama“ and then when the commit option is finished, from the same menu select “Push to Device”