NGAF Passive Vulnerability Scan

AimanHakim Lv2Posted 31 Oct 2023 10:18

Last edited by AimanHakim 31 Oct 2023 10:19.

Hi guys, I have a problem regarding the passive vulnerability scanning for the Business Asset Security. Even though I've enabled the passive scanning in policy, no data. Here's my output:



Here's my configurations for the policy. For clarification the virtual untrust is the WAN zone while the trust is the LAN zone. The template used for Basic Protection and Detection and Response is default template.


The passive vulnerability scanning is enabled


So far the other features in SOC such as Summary and Attack Events in Business Asset Security and User Security works. Btw, all policy are allow all.

So here are my questions:

1. Is that is it possible the scanned servers are so well protected that there's no output generated?
2  If it's not, then is my configurations are wrong then?

RegiBoy has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

The scanned servers may be well-protected, resulting in no output being generated by the passive vulnerability scanning. Passive vulnerability scanning relies on analyzing network traffic and documents to gather information about the systems and software versions in use by a company
Is this answer helpful?
RegiBoy Lv5Posted 08 Nov 2023 15:29
  
The scanned servers may be well-protected, resulting in no output being generated by the passive vulnerability scanning. Passive vulnerability scanning relies on analyzing network traffic and documents to gather information about the systems and software versions in use by a company
isabelita Lv3Posted 08 Nov 2023 15:34
  
There may be a configuration issue with the policy or the passive vulnerability scanning feature. Double-check the policy configurations to ensure that the passive vulnerability scanning is enabled correctly.
Noah19 Lv3Posted 08 Nov 2023 15:35
  
Check the documentation and support resources for the specific security solution or tool you are using to see if there are any known issues or troubleshooting steps related to passive vulnerability scanning.
VanFlyheights Lv3Posted 08 Nov 2023 15:37
  
Contact the vendor or support team for the security solution or tool you are using to get assistance with troubleshooting the issue.









































































































soneosansan Lv3Posted 08 Nov 2023 15:39
  
Ensure that the passive vulnerability scanning feature is correctly configured in your security policy. Double-check the policy settings, and make sure that the passive scanning feature is properly enabled.
Carem Lv2Posted 08 Nov 2023 15:40
  
Confirm that the firewall rules are correctly configured to allow the traffic needed for passive scanning. If the traffic is blocked, the scanning data won't be collected. Ensure that the scanning traffic is allowed in your security policy.
Rica Cortez Lv2Posted 08 Nov 2023 15:42
  
Servers must be identify first and make an object
JoanaPatricia Lv2Posted 08 Nov 2023 15:42
  
It's possible that the servers you are scanning are indeed well-protected and have no known vulnerabilities. Passive scanning relies on identifying vulnerabilities based on the network traffic and behavior. If your servers are up-to-date with patches and well-secured, there may be no vulnerabilities to report.
damulagski Lv3Posted 08 Nov 2023 15:43
  
Passive scanning may take some time to collect sufficient data and identify vulnerabilities. The lack of immediate results doesn't necessarily mean something is wrong. Give it some time to collect data and generate reports.

I Can Help:

Change

Moderator on This Board

1
131
3

Started Topics

Followers

Follow

18
8
0

Started Topics

Followers

Follow

Board Leaders