Integration Limitations

  • Compliance and Auto-Discovery are mutually exclusive. Compliance scanning is unavailable when the Auto-Discovery feature is enabled.

  • Auto-Discovery requires vCenter/ESXi 7.0.3 or later, and requires a vCenter credential (it is not available with an ESXi-only credential).

  • Mixed-version environments are unsupported where the REST API is not available on all hosts (for example, vCenter 7.0.3 managing ESXi earlier than 7.0.3).

  • Scanner topology constraint. Tenable recommends using a scanner group containing a single scanner with Auto-Discovery credentials, and entering only a single initial host in the scan. Multiple scanners in an Auto-Discovery scan can cause discovered targets to be scanned more than once.

  • Plugin family dependency. ESXi vulnerability detection plugins belong to the VMware ESX Local Security Checks plugin family. If that family is disabled, scan results do not include those detections.

VMware vCenter support matrix

Feature Requires Authentication Supported vCenter Version
Vulnerability Management No 7.x, 8.x
Auto-Discovery Yes 7.0.3+, 8.x
Audit / Compliance Yes 6.x, 7.x, 8.x
VIB Enumeration Yes 7.0.3+, 8.x
Active / Inactive VMs Yes 7.0.3+, 8.x