Linked Scanning Overview

Tenable Security Center supports two ways to use a Tenable Nessus scanner for active scanning:

  • Active (managed) scannersTenable Security Center connects directly to the Tenable Nessus scanner over the network, as described in Add a Tenable Nessus Scanner.

  • Linked scanners — the Tenable Nessus scanner connects to Tenable Security Center through a Tenable Sensor Proxy. Sensors communicate with the Sensor Proxy rather than with Tenable Security Center directly. As a result, large numbers of scanners can communicate with Tenable Security Center while using less bandwidth and a simpler network configuration.

For information on how to used linked scanners, see Link a Sensor Proxy to Tenable Security Center and Add a Linked Tenable Nessus Scanner.

Components

Component

Role in linked scanning

Tenable Security Center

Schedules and initiates scans, resolves scan zones, and retrieves and reports results.

Tenable Sensor Proxy

An on-premises cache and single point of traffic between your sensors and Tenable Security Center. You must link the Sensor Proxy to Tenable Security Center first.

Linked Tenable Nessus scanner

A Tenable Nessus scanner linked to the Sensor Proxy. Performs the scan jobs that Tenable Security Center assigns.

Communication and ports

Connection

Direction

Port

Sensor Proxy to Tenable Security Center

Outbound from the Sensor Proxy

TCP 8837

Tenable Nessus scanner to Sensor Proxy

Inbound to the Sensor Proxy

TCP 443

Note: A single linking key applies to all sensors that connect through a Sensor Proxy, including Tenable Nessus scanners, Tenable One Web App Scanning scanners, and Sensor Proxies. You can regenerate the linking key at any time. When you regenerate the linking key, sensors that linked with a previous key continue to work.

How linked scans differ from active scans

The most important behavioral difference is how Tenable Security Center enforces scan zone IP ranges:

Behavior

Active (legacy) scans

Linked scans

Scan zone IP range enforcement

Enforced only during Automatic Distribution. When you select a specific scan zone, Tenable Security Center ignores the zone's IP ranges and scans all targets that you specify in the scan configuration. Remediation scans always enforce ranges.

Always enforced, whether you use Automatic Distribution or select a specific scan zone.

Connection to Tenable Security Center

Direct, over the network.

Through a Sensor Proxy.

Plugin updates

Pushed by Tenable Security Center for managed scanners.

Handled through the linked scanner pipeline.

Custom plugin support

Supported.

Not supported. Linked scanners do not support custom plugins.

Freeze window enforcement

Applied at scan start and during scan execution. Tenable Security Center stops active scans when a freeze window begins.

Applied at scan start time only. Tenable Security Center does not stop in-flight scans when a freeze window begins.

Stop behavior

Stops promptly when you click Stop.

May take up to 30 minutes in edge cases, because the scanner must acknowledge the stop request. Most scans stop within seconds to a couple of minutes. If a linked scan remains in a Stopping state for more than 30 minutes, Tenable Security Center force-stops the scan.

Note: When you use Stop & Import Results with a linked scan, Tenable Security Center imports results at the chunk level, not the individual IP level. If no chunk has fully completed when the scan stops, no results are imported and the scan finishes with a Stopped status. Individual IPs that appear as completed in the scan progress are not imported if their chunk did not finish.

Note: Because linked scans always enforce scan zone IP ranges, confirm that your scan zone ranges cover the targets that you intend to scan. A scan fails if any target is not covered by an eligible scan zone. For more information, see Scan Zones.

Scan Rollover Behavior

When you stop a scan that uses linked scanners and choose to roll over, Tenable Security Center imports any results that have already been returned and schedules a rollover scan to cover the targets that were not yet scanned. Because linked scans divide their targets into groups scanned in parallel and track progress by group, the rollover scan covers the targets of any group that had not fully finished when the scan was stopped. A small number of hosts already scanned within a group still in progress may be scanned again in the rollover scan. No targets are skipped.

Choosing between linked and active scanners

When a scan's targets fall within scan zones that contain both a linked and an active Tenable Nessus scanner, Tenable Security Center uses the organization-level Prefer Linked Scan Zones preference to determine which scanner type to use. For more information, see Prefer Linked Scan Zones in the Organization Settings.

What to do next