Chapter 7: Configuring Discovery and Assessment Policies
108
IBM Internet Security Systems
Account Verification
This setting applies only if an Assessment Credentials policy is
available for the group being scanned.
Verify account access level before using
•
If disabled, Enterprise Scanner assumes that whatever is
specified in the Assessment Credentials policy is accurate.
•
If enabled, Enterprise Scanner tries to confirm that the access
level specified in the Assessment Credentials policy is correct.
Important:
You should enable the
Check local group
membership to verify access level
if you enable account
verification.
Access domain controller to verify access level
•
If disabled, Enterprise Scanner does not communicate with a
Domain Controller in the process of verifying access levels.
•
If enabled, Enterprise Scanner tries to communicate with a
Domain Controller in the process of verifying access levels.
Check local group membership to verify access level
•
If disabled, Enterprise Scanner does not try to confirm the
account’s access level during assessment by checking which
local groups the asset belong to.
•
If enabled, Enterprise Scanner tries to confirm the account’s
access level during assessment by checking which local
groups the asset belong to.
Account Lockout Control
Allowed account lockout:
This setting controls how Enterprise
Scanner handles accounts that have account lockout protection
enabled.
The account lockout options are as follows:
•
No lockout allowed
—Enterprise Scanner avoids running
password guessing checks if account lockout is enabled on the
target host, or if its status could not be determined.
•
Temporary lockout allowed
—Enterprise Scanner runs
password guessing checks only if the account lockout duration
is less than or equal to the value specified in the
Longest
allowed temporary lockout
option below.
•
Permanent lockout allowed
—Enterprise Scanner runs
password guessing checks even if the account lockout
duration is set to run infinitely.
Longest allowed temporary lockout
x
(minutes)
Specifies the maximum time (in minutes) that accounts are
allowed to be locked out by password guessing checks. This value
applies only if Temporary Lockout Allowed is enabled. When
temporary lockout is allowed, password guessing checks are run
only against assets whose lockout policy disables locked out
accounts for no more than the maximum allowed lockout time.
Setting
Description
Summary of Contents for Proventia Network Enterprise
Page 1: ...IBM Internet Security Systems IBM Proventia Network Enterprise Scanner User Guide Version 1 3 ...
Page 8: ...8 Contents IBM Internet Security Systems ...
Page 14: ...Preface 14 IBM Internet Security Systems ...
Page 15: ...Part I Getting Started ...
Page 16: ......
Page 69: ...Part II Configuring Enterprise Vulnerability Protection ...
Page 70: ......
Page 80: ...Chapter 5 Introduction to Enterprise Scanner Policies 80 IBM Internet Security Systems ...
Page 120: ...Chapter 8 Defining Agent Policies 120 IBM Internet Security Systems ...
Page 121: ...Part III Scanning ...
Page 122: ......
Page 134: ...Chapter 9 Understanding Scanning Processes in SiteProtector 134 IBM Internet Security Systems ...
Page 150: ...Chapter 10 Monitoring Scans 150 IBM Internet Security Systems ...
Page 164: ...Chapter 11 Managing Scans 164 IBM Internet Security Systems ...
Page 165: ...Part IV Analysis Tracking and Remediation ...
Page 166: ......
Page 190: ...Chapter 13 Tracking and Remediation 190 IBM Internet Security Systems ...
Page 197: ...Part V Maintenance ...
Page 198: ......
Page 212: ...Chapter 16 Updating Enterprise Scanner 212 IBM Internet Security Systems ...
Page 218: ...Chapter 16 Updating Enterprise Scanner 218 IBM Internet Security Systems ...
Page 224: ...Chapter 16 Updating Enterprise Scanner 224 IBM Internet Security Systems ...
Page 252: ...Chapter 18 Enterprise Scanner Logs and Alerts 252 IBM Internet Security Systems ...
Page 258: ...Glossary 258 IBM Internet Security Systems ...
Page 268: ......