Scan Configuration — VMware ESX SOAP API
Complete the following steps to configure Tenable Nessus with the VMware ESX SOAP API integration.
Note: Access to VMware servers is available through its native SOAP API. VMware ESX SOAP API allows you to access the ESX and ESXi servers via username and password.
-
Log in to your Tenable Nessus user interface.
-
In the left navigation pane, click Scans.
The Scans page appears.
-
In the upper-right corner of the page, click Create a Scan.
The Select a Scan Template page appears.
-
Select the Advanced Network Scan template.
The scan configuration page appears.
-
In the Name box, type a name for the scan.
-
In the Targets box, type the IP addresses of the ESXi host or hosts.
-
(Optional) Add a description, folder location, scanner location, and target groups.
-
Click the Credentials tab.
The Credentials pane appears.
-
Next to Add Credentials, click the add button, then in the Miscellaneous section select VMware ESX SOAP API.
The Settings pane for the selected credential appears.
-
Configure each option below for the selected credential.
Option Description Required ESX SOAP API Authentication Method Choose from the available authentication methods: Username and Password (manual entry)
PAM Integration (use a specific PAM to gather authentication credentials from the available list)
Yes Username The username associated with the local ESXi account. Yes (if Username and Password authentication is selected) Password The password associated with the local ESXi account. Yes (if Username and Password authentication is selected) Do not verify SSL Certificate When enabled, Tenable does not validate the SSL certificate for the ESXi server. Disable this toggle if your ESXi host uses a certificate signed by a trusted CA. Disabled by default. No -
Do one of the following:
-
To save without launching the scan, click Save.
-
To save and launch the scan immediately, click Launch.
-
Note: If you scheduled the scan to run at a later time, the Save & Launch option is not available.