I am looking for recommendations on whitelisting a Tenable PCI ASV Scan?
I am also a little confused, I setup web server protection via a WAF Rule, this is all working now, however when I run the new scan I now get-
HIGHPCI DSS Compliance : Scan Interference
Description
Interference from either the network or the host did not allow the scan to fulfill the PCI DSS scan validation requirements. This report is insufficient to certify this server. There may be a firewall, IDS or other software blocking Nessus from scanning.
Solution
- Adjust Nessus scan settings to improve performance.
- Whitelist the Nessus scanner for any IDS or Firewall which may be blocking the scan.
Isn't the point of the protection to help with security, if I whitelist the scanner the security will not be used so yyeeeahhhh..............
(Honestly I think they want you to resolve any issues on the webserver and use the protection but it still seems silly)
This thread was automatically locked due to age.