Qualys Scanner - Static Route Configuration

Qualys allows the configuration of static routes on both virtual and physical scanners. This allows the scanner to direct non-local traffic to the appropriate gateway address when this address is not the default gateway. This configuration may be useful when a scanner is placed on a transit network containing multiple routers for different destinations, such as for remote facilities or business partner network connections.

Required Information

In order to configure your appliance with static routes you will need the following information:

Gateway IP address – The scanner-facing IP address of the router or gateway.  There is no requirement for uniqueness, the same gateway may be used for multiple target networks.

Target network address in CIDR format – The gateway/target network pair must be unique. The same gateway/target network pair cannot be defined in another static route configuration for the same appliance. The target network must have a valid starting IP address for the target mask provided.

A route name to identify the static route configuration in the static routes list.

Limitations

Static routes cannot be configured on any of the public cloud provider-specific virtual scanner images (AWS, Azure, GCP, etc.).

Physical scanners support up to 99 static routes.

Virtual scanners support up to 4094 static routes as long as you are using the latest appliance software distribution. Previous versions support up to 99.

Configure Static Routes in the UI

To configure static routes from the Qualys Enterprise TruRisk™ Platform, perform the following steps:

1) Log in to Qualys as a Manager, go to Scans > Appliances, select the appliance, and choose Info from the Quick Actions menu.
The Info page displays the scanner's network configuration.
Within the LAN and WAN settings sections, you can view the following information for each network interface:

  • Assigned IP address
  • Netmask
  • Default gateway
  • Configured DNS servers

Scanner App Info

Before proceeding to the next step and adding static routes to the scanner, review the following routing behavior and design considerations.

Route Selection Behavior

The Qualys scanner determines the path to a destination network or IP address based on standard routing principles. When multiple routes are available, the scanner selects the route that has the most specific match, known as the longest prefix match, from its routing table.

DNS and Gateway Route Validation

The Qualys scanner is designed to ignore any static route configurations received from the Qualys TruRisk platform if any of the following addresses fall within a configured static route:

  • LAN DNS servers
  • WAN DNS servers
  • LAN default gateway
  • WAN default gateway
  • Proxy IP address

This behavior applies even when the DNS server addresses are located outside the corresponding LAN or WAN subnet.

According to the rules mentioned above, the static routes in the following examples are rejected:

Example 1

Scanner’s LAN configuration

LAN subnet: 192.168.10.0/24

Gateway IP: 192.168.10.1

Static route created via TruRisk platform:

Destination network: 192.168.10.0/28

Next hop: 192.168.10.4

Explanation

The gateway IP (192.168.10.1) falls within the destination network (192.168.10.0/28, range 192.168.10.0–192.168.10.15). Qualys would reject this configuration because the LAN gateway IP is contained within the static route network.

Example 2

Scanner’s LAN DNS configuration
DNS servers:

10.20.30.53

10.40.20.4

Static route created via TruRisk platform:

Destination network: 10.40.20.0/24

Next hop: 10.40.20.1

Explanation

The DNS server IP (10.40.20.4) belongs to the destination network (10.40.20.0/24). Therefore, the DNS server is located within the address range covered by the static route, and the Qualys scanner would reject this configuration.

2) Select the Static Routes tab on the left. Click New, then click OK once you have read and understood the warning.

static routes configured on the appliance

3) When the Edit Route dialog box appears enter the required information and click OK.

edit route information

4) Click Save once all your Add/Change/Delete operations have been completed.

IPv6 Support for Static Routes

The IPv6 Scanning feature must be enabled for your account. Please contact Support or your Technical Account Manager if you would like have this feature turned on.

You must enable IPv6 on the scanner to add IPv6 configurations. Select “Enable IPv6 for this scanner” on the LAN Settings tab.

enable I P v 6 check box for the scanner option

On the Static Routes tab you’ll see IPv4 and IPv6 configurations that have been configured for the appliance.

static routes with I P v 4 and I P v 6 configurations

When you create or edit a static route, you can add IPv4 details, IPv6 details or both.

Edit Route dialog