Forum Discussion

Tealer_315926's avatar
Tealer_315926
Icon for Nimbostratus rankNimbostratus
Nov 15, 2017

Whitelist Qualys Scanner - F5 Big-IP VE

I have searched around F5 DevCentral and forums, but can't find an answer, so apologies if I'm asking a question that has already been asked. We are being scanned for PCI compliance by Qualys, and we are getting a fail for 86732 - Exhaustive Web Testing Skipped. Qualys have reduced the bandwidth setting, but still getting the fail. We have a Big-IP VE, running APM. I've had a look through and cannot see an obvious way for me to whitelist the source address on the existing VIP facing the Internet. I have seen articles about ASM, but we do not have ASM. Can anyone point me in the right direction? Any help appreciated.

 

1 Reply

  • this is perhaps clear to you but what does this actually mean: "86732 - Exhaustive Web Testing Skipped"?

     

    do you want the Qualys scanner to bypass the APM authentication? does it even authenticate now?

     

    you could setup another VIP without APM profile and put a source for the Qualys scanner IP, would that be enough?