Scan Using Virtual Scanner Appliance

Scanning with virtual scanner appliance involves following sequence of steps.

EC2 Scan Workflow

Qualys provides a special EC2 Scan (and Schedule EC2 Scan) workflow which only works in collaboration with an instance of the scanning virtual appliance AMI. This solution allows on-demand and scheduled scanning in Amazon EC2-Classic and EC2-VPC, without the need for the customer to manually request scanning permission from AWS.


vm-new-ec2-scan

Provide scan settings:

  1. Give your scan a title and select the option profile you configured with authentication (required for vulnerability scan).
  2. Select the EC2 connector name you configured.
  3. For Platform, choose one of EC2 Classic, EC2 VPC (All VPCs in region) or EC2 VPC (Selected VPC). Based on your selection you need to select region(s).
  4. Select asset tags - these are assets activated for your connector.

    ec2-scan1

  5. Choose the Virtual Scanner Appliance AMI you have launched in Amazon EC2.

    ec2-scan2

  6. Click Launch and start scanning and securing your Amazon EC2 infrastructure.

Before you launch the scan, the EC2 Vulnerability Scan Preview lists all the instances (including terminated instances). However, during the scan all such terminated instances ignored from the scan.

EC2_instances_scan

Scanning EC2 Classic Instances

Choose EC2 Classic (Selected Region) to scan EC2 classic hosts in a region. When selected we’ll only scan EC2 Classic instances in the region.

scan-platform1

Scanning VPC Instances

Choose EC2-VPC (Selected VPC) to scan only a VPC you select.

scan-platform2

Scanning Instances using VPC Peering

Choose EC2-VPC (All VPCs in Region) to scan all VPCs in a region. Select this option ONLY if there is peering between all the VPCs in the region, or you could end up with Host not found errors for instances where your Virtual Scanner Appliances cannot reach them.

Scanning EC2 Instances in GovCloud

Follow the instructions below to secure your AWS GovCloud using Qualys Virtual Scanner Appliance (qVSA).

  1. Contact your Qualys TAM or Qualys Support requesting access to
    • GovCloud Feature and
    • Qualys Virtual Scanner Appliance AMI
  2. Include your AWS Account ID under which you would be running the scanner. Access to the AMI is enabled by Qualys support for specific Account IDs.
  3. Qualys Support sends you an email with approval and access information.
  4. Create a Qualys Virtual Scanner Instance with the qVSA AMI, now available under MyImages section in the Create Instance wizard. (If you need to search, use the keyword qVSA to find the Qualys scanner).
  5. Configure the Virtual Scanner Instance as described in Scanner Deployment
  6. You are ready to start scanning! Just follow the steps in Scan Using Virtual Scanner Appliance