Scan Configuration

IMPORTANT: The RNA utilizes external IPs as the source of scanning traffic for external scans. To find the detailed list to add to your allow-list, see External RNA IPs.

Web Application Scanning

Web Application Scanning (WAS) scanners provide comprehensive, updated information about your web application’s security posture. Scan audit and tuning policies define how targets are scanned. WAS has default policies for several common scanning objectives, and custom policies can be configured as well.

This page details the following topics:

  • Viewing, modifying, and creating audit policies
  • Viewing, modifying, and creating tuning policies

Reducing the number of audit/crawler/bruting processes and/or increasing the request delay can be used to throttle the scanner back to send data per second. Processes should be throttled back starting with the bruting processes, then the crawler processes, and finally the audit processes to minimize impact on the overall scan duration. Any changes to number of processes, request timeout or request delay will impact scan time.

Work with Audit Policies

An audit policy specifies which vulnerabilities and allowances to include in the scan.

To view audit policies
  1. From the navigation menu, select Scans > Scan Policies.
  2. Select the Audit tab. The Available Audit Policies page lists the scan audit policies with a brief description.
  3. Select an audit policy from the list to view its settings.
To modify or create an audit policy
  1. From the navigation menu, select Scans > Scan Policies.
  2. Select the Audit tab.
  3. Perform one of the following:
    • Select an audit policy name to modify it.
    • NOTE: You cannot modify default audit policies, which are denoted with a shield symbol, but you can select to copy the default policy using the copy icon to create a new audit policy with the same configuration. Once the audit policy is copied, you can modify the settings for the copy.
    • Select + New audit policy to create a new policy.
  4. Enter or modify the policy settings on the following sections and associated fields:

  5. Select Save.

Work with Tuning Policies

A tuning policy specifies scan performance settings.

NOTE: For PCI scans, the PCI type tuning policy must be used. Standard tuning policies cannot be used for PCI scans. Some elements of the PCI tuning policy are locked for compliance reasons.
To view tuning policies
  1. From the navigation menu, select Scans > Scan Policies.
  2. Select the Tuning tab. The Available Tuning Policies page lists the scan tuning policies with a brief description.
  3. Select a tuning policy from the list to view its settings.

To modify or create a tuning policy:
  1. From the navigation menu, select Scans > Scan Policies.
  2. Select the Tuning tab.
  3. Perform one of the following:
    • Select a tuning policy name to modify it.
    • NOTE: You cannot modify default tuning policies, which are denoted with a shield symbol, but you can select to copy the default policy using the copy icon to create a new policy with the same configuration. Once the tuning policy is copied, you can modify the settings for the copy.
    • Select + New tuning policy to create a new policy.
  4. Enter or modify the policy settings on the following sections and associated fields:

  5. Select Save.