Scan Configuration — VMware vCenter API
Complete the following steps to configure Tenable Nessus with the VMware vCenter API integration.
-
Log in to your Tenable Nessus user interface.
-
In the left navigation pane, click Scans.
The Scans page appears.
-
In the upper-right corner of the page, click Create a Scan.
The Select a Scan Template page appears.
-
Select the Advanced Network Scan template.
The scan configuration page appears.
-
In the Name box, type a name for the scan.
-
In the Targets box, type the IP addresses of the vCenter host and, if you are not using Auto-Discovery, the ESXi host or hosts.
-
(Optional) Add a description, folder location, scanner location, and target groups.
-
Click the Credentials tab.
The Credentials pane appears.
-
Next to Add Credentials, click the add button, then in the Miscellaneous section select VMware vCenter API.
The credential options appear.
-
Configure each option below for the selected credential.
Option Description Required vCenter Host The IP address or hostname of the vCenter instance. Yes vCenter Port The TCP port that vCenter listens on for communications from Tenable. By default, Tenable uses 443. Yes HTTPS When enabled, Tenable connects using secure communication (HTTPS). When disabled, Tenable connects using standard HTTP. Yes Verify SSL Certificate When enabled, Tenable verifies that the SSL certificate on the server is signed by a trusted CA. If you are using a self-signed certificate, disable this setting. No vCenter API Authentication Method Choose from the available authentication methods: Username and Password (manual entry)
PAM Integration (use a specific PAM to gather vCenter API authentication credentials from the available list)
Yes Username The username for the vCenter server account that Tenable uses to perform checks on the target system. Yes (if Username and Password authentication is selected) Password The password for the vCenter server user. Yes (if Username and Password authentication is selected) Use Auto Discovery Option that toggles on access to configure host and virtual machine auto-discovery. No Auto Discover Managed VMware ESXi Hosts Adds any discovered VMware ESXi hypervisor hosts to the scan targets you include in your scan. No Auto Discover Managed VMware ESXi Virtual Machines Adds any discovered VMware ESXi hypervisor virtual machines to the scan targets you include in your scan. No Report Active and Inactive Virtual Machines Enables collection of virtual machines for active and inactive VM reports. Disabling this option reduces the overall number of requests made by the scanner. No -
Do one of the following:
-
To save without launching the scan, click Save.
-
To save and launch the scan immediately, click Launch.
-
Note: If you scheduled the scan to run at a later time, the Save & Launch option is not available.