Manage Nodes

Required user role when using Tenable Nessus Manager: Administrator or System Administrator

Use the following procedures to manage nodes in your clusters. For more information, see Clustering.

Get Linking Key from Node

You need the linking key from the cluster parent node to link child nodes or migrate agents to the cluster. Similarly, you need the linking key from the cluster child node to link an agent to the child node directly.

Note: You can also retrieve your child node linking key from the nessuscli. For more information, see nessuscli fix --secure --get child_node_linking_key in the nessuscli Fix Commands section.

Before you begin:

To get the linking key from the node:

  1. In the top navigation bar, click Sensors.

    The Linked Agents page appears. By default, Linked Agents is selected in the left navigation menu and the Linked Agents tab is active.

  2. In the left navigation bar, click Agent Clustering.

    The Cluster Groups page appears.

  3. Copy or make note of the Linking Key.

Link a Node

To link a child node to a cluster, you install an instance of Tenable Nessus as a cluster child node, then configure the node to link to the parent node of the cluster.

Note: Before you begin, you must get the linking key from the cluster parent node. This is because you have to complete the Link the child node to the parent node process in one session. Starting the process and then navigating away from the user interface before completing the process can disable the child node user interface prematurely.

To install and configure Tenable Nessus as a child node:

  1. Install Tenable Nessus as described in the appropriate Install Tenable Nessus procedure for your operating system.
  2. On the Welcome to Nessus, select Link Nessus to another Tenable product.

  3. Click Continue.

    The Managed Scanner screen appears.

  4. From the Managed by drop-down box, select Nessus Manager (Cluster Node).

  5. Click Continue.

    The Create a user account screen appears.

  6. Create a Tenable Nessus administrator user account, which you use to log in to Tenable Nessus:
    1. In the Username box, enter a username.
    2. In the Password box, enter a password for the user account.
  7. Click Submit.

    Tenable Nessus finishes the configuration process, which may take several minutes.

To link the child node to the parent node:

  1. In the Tenable Nessus child node, use the administrator user account you created during initial configuration to sign in to Tenable Nessus.

    The Agents page appears. By default, the Node Settings tab is open.

  2. Enable the toggle to On.
  3. Configure the General Settings:
    • Node Name — Type a unique name that identifies this Tenable Nessus child node on the parent node.
    • (Optional) Node Host — Type the hostname or IP address that Tenable Agents should use to access the child node. If you do not provide a host node, Tenable Agent uses the system hostname. If Tenable Agent cannot detect the hostname, the link fails.
    • (Optional) Node Port — Type the port for the specified host.
  4. Configure the Cluster Settings
    • Cluster Linking Key — Paste or type the linking key that you copied from the Tenable Nessus Manager parent node.
    • Parent Node Host — Type the hostname or IP address of the Tenable Nessus Manager parent node to which you are linking.
    • Parent Node Port — Type the port for the specified host. The default is 8834.
    • (Optional) Use Proxy — Select the checkbox if you want to connect to the parent node via the proxy settings set in Proxy Server.
  5. Click Save.

    A confirmation window appears.

  6. To confirm linking the node to the parent node, click Continue.

    The Tenable Nessus child node links to the parent node. Tenable Nessus logs you out of the user interface and disables the user interface.

    Note: Once you disable the child node user interface, subsequent attempts to access the child node user interface result in the following error: error: The requested file was not found.

What to do next:

  • Log in to the Tenable Nessus Manager parent node to manage linked Tenable Agents and nodes.
  • Link or migrate agents to the cluster.
  • On the Tenable Nessus Manager parent node, manage cluster groups to organize your nodes into groups that conform to your network topology. You must segment your network with cluster groups when certain agents only have access to certain child nodes. By default, Nessus assigns the node to the default cluster group.

View or Edit a Node

On Tenable Nessus Manager with clustering enabled, you can view the list of child nodes currently linked to the parent node. Tenable Nessus assigns these child nodes to cluster groups. You can view details for a specific node, such as its status, IP address, number of linked agents, software information, and plugin set. If agents on the node are currently running a scan, a scan progress bar appears.

You can edit a node's name or the maximum number of agents that can be linked to the child node.

To view or edit a child node:

  1. In the top navigation bar, click Sensors.

    The Linked Agents page appears. By default, Linked Agents is selected in the left navigation menu and the Linked Agents tab is active.

  2. In the left navigation bar, click Agent Clustering.

    The Cluster Groups page appears.

  3. In the cluster groups table, click the row of a cluster group that contains child nodes.

    The Cluster Nodes tab appears. The Cluster Nodes table describes the following information about each cluster node:

    Column Description
    Name The child node name.
    Status

    The child node's current state:

    • Idle — The node is inactive and is not scanning or rebalancing.

    • Idle (disabled) — The node is manually disabled via the button.

    • Scanning — The node is scanning.

    Scans The count of in-progress scans the child node is participating in.
    Usage

    This column indicates how many agents are currently linked to the node compared to its maximum capacity.

    Note: You can configure the maximum agents per node later in step 8.

    Last Connected The last day and time the child node communicated with the parent node.
    Link Click to disable or enable the child node in the cluster group.
    Delete Click to remove the child node from the cluster group.
  4. Click the row of the child node you want to view.

    Tenable Nessus Manager shows the Node Details tab.

  5. In the Node Details tab, view detailed information for the selected node.
  6. To move the node to another cluster group, do the following:
    1. Next to Cluster Group, click the button.

      The Change Cluster Group dialog box appears.

    2. In the drop-down menu, select a different cluster group.
    3. Click Save.

      The node moves to another cluster group.

  7. To edit node settings, click the Settings tab.

  8. Edit any of the following:

    • Node Name  — Type a unique name to identify the node.
    • Max Agents  — Type the maximum number of agents that can be linked to the child node. The default value is 10,000 and the maximum value is 20,000.
  9. Click Save.

    Tenable Nessus Manager updates the node settings.

Enable or Disable a Node

If you disable a child node, its linked Tenable Agents relink to another available child node in the same cluster group. If you re-enable a child node, Tenable Agents may become unevenly distributed, at which point you can choose to Rebalance Nodes.

To enable or disable child nodes:

  1. In the top navigation bar, click Sensors.

    The Linked Agents page appears. By default, Linked Agents is selected in the left navigation menu and the Linked Agents tab is active.

  2. In the left navigation bar, click Agent Clustering.

    The Cluster Groups page appears.

  3. In the cluster groups table, click the row of a cluster group that contains child nodes.
  4. In the row of a child node, do one of the following:

    • To disable a node:
      1. Hover over the  button, which becomes .
      2. Click the button.

        Tenable Nessus Manager disables the child node.

    • To enable a node:
      1. Hover over the .  button, which becomes .
      2. Click the  button.

        Tenable Nessus Manager enables the child node.

Rebalance Nodes

Tenable Agents may become unevenly distributed across child nodes for various reasons: a child node or multiple child nodes may be temporarily unavailable, disabled, deleted, or recently added. Events such as these negatively impact the cluster's performance. When the imbalance passes a certain threshold, Tenable Nessus Manager gives you the option to rebalance child nodes. This threshold is passed when one or both of the following criteria are met:

  • 10% of your agents are not ideally distributed, based on your nodes' ideal capacity.

  • A single node has at least 5% more agents than the node's ideal capacity.

    Example:

    Your organization has four nodes and 100 linked agents. To evenly distribute linked agents across four nodes, Tenable Nessus Manager should assign each node 25% of the total linked agents which, in this case, would be 25 linked agents per node.

    Tenable Nessus Manager gives you the option to rebalance child nodes if either:

    • Tenable Nessus Manager can redistribute 10% or more of your linked agents (in this example, 10 linked agents or more) for better results. For example, if two of your nodes have 20 linked agents and two of your nodes have 30 linked agents, Tenable Nessus Manager would allow you to rebalance the nodes to reach the ideal 25-25-25-25 distribution.

    • One of your nodes reaches 30% of its capacity (in this example, ~33 linked agents)

When you rebalance child nodes, Tenable Agents get redistributed more evenly across child nodes within a cluster group. Tenable Agents unlink from an overloaded child node and relink to a child node with more availability.

To rebalance child nodes:

  1. In the top navigation bar, click Sensors.

    The Linked Agents page appears. By default, Linked Agents is selected in the left navigation menu and the Linked Agents tab is active.

  2. In the left navigation bar, click Agent Clustering.

    The Cluster Groups page appears.

  3. In the cluster groups table, click the row of a cluster group.
  4. In the upper-right corner of the page, click Rebalance Nodes.

    Tenable Nessus Manager rebalances the Tenable Agent distribution across child nodes.

Delete a Node

When you delete a child node, linked Tenable Agents eventually relink to another available child node in the same cluster group. The agents may take longer to relink if you delete a node compared to if you disable the node instead.

If the node you want to delete is the last node in a cluster group with linked agents, you must first move those agents to a different cluster group. If you only want to disable a child node temporarily, see Enable or Disable Nodes.

To delete a child node:

  1. In the top navigation bar, click Sensors.

    The Linked Agents page appears. By default, Linked Agents is selected in the left navigation menu and the Linked Agents tab is active.

  2. In the left navigation bar, click Agent Clustering.

    The Cluster Groups page appears.

  3. In the cluster groups table, click the row of a cluster group that contains child nodes.
  4. In the row of the child node you want to delete, click the button.

    The Delete Agent Node dialog box appears.

    Note: If you delete a node, you cannot undo this action.

  5. To confirm you want to delete the child node, click Delete.

    Tenable Nessus Manager deletes the child node.