Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 
Custom Alert Banner

3rd party vulnerability scan

f5mkuDefault
Cirrus
Cirrus

Hi Experts,

 

I'd like to get some help with another issue.

 

We have this new 3rd party vendor that will be scanning the webservices hosted in LTM. The Big-IP also runs with ASM.

We tested between 15 virtual servers and only 1 is able to scan successfully.

 

Is there a setting that we need to perform on the Big-IP level to make the scan successfully work?

Is there a setting at real server level that we also need to adjust?

 

The virtual server by the way does port forwarding from port 443 to port 80 and there is certificate installed in F5 clientssl.

 

Hoping someone can advise.

 

Thank you in advance,

4 REPLIES 4

PeteWhite
F5 Employee
F5 Employee

What do you mean by "We tested between 15 virtual servers and only 1 is able to scan successfully". How does it fail? This does not sound like an F5 problem - can they get basic access to the service? Is ASM blocking the malicious traffic?

Hi Pete, sorry for late response. We actually tested again focused on 1 specific website and confirmed that the scanner is able to hit the main page of the website. However the scan will stop. Base from the ASM we see some events from scanner to VS hitting some page. It looks like the real server is the one causing some issues. Not too sure if its a permission issue. Any idea what we need to adjust on the real server end?

the webservices work fine for users i assume?

 

it sounds very much like a scanner issue, if you use it without F5 and or without ASM does it function fine? if not then talk with the scanner people and understand why it "stops".

 

 

yes, the webservices works fine for the users, this is what we keep mentioning to the vendor, also in ASM event logs we can see ASM is recommending to block but the response is not accepted. means F5 don't accept the recommendation since we have whitelisted the scanner IP address. With or without the ASM is just the same, we suspect its on the webserver (real server) maybe some permission gets denied since scanner can hit the main page but subpages cannot.

 

we'll update this thread once it gets resolve. thank yiou