Advanced Nessus configurations and scan policies for network uptime
We explore how to move beyond basic out-of-the-box templates and understand how Tenable Nessus behaves under the hood. You will learn how simple adjustments can slash your total scan execution time while completely protecting your network uptime.
[00:06:55] Nessus advanced global performance settings
We start by taking a look under the hood at advanced global performance settings, which establish the maximum performance boundaries for the entire scanner instance across all active and scheduled jobs.
- Scanner host impact: Measures the load placed on the physical or virtual machine running Tenable Nessus, specifically CPU core utilization and RAM allocation.
- Target asset impact: Measures the burden placed on the endpoint being scanned, including its CPU, memory buffers, and local TCP connection pool.
- Network infrastructure impact: Measures the strain placed on intermediate devices like switch ports, routers, and stateful firewalls.
[00:11:02] Concurrency and scale controls
Concurrency and scale control settings dictate the macro-level breadth and parallel processing capabilities of your scan engine.
- Max concurrent scans: Sets the ceiling on how many separate scan tasks run simultaneously, which heavily impacts your scanner's CPU and memory footprint.
- Global max hosts concurrently scanned: Controls the total number of target IP addresses evaluated in parallel. Increasing this maximizes network sweep speed but risks saturating intermediate firewalls.
- Max concurrent checks per host: Defines the maximum number of plugins executing on a single asset. Lowering this ensures fragile devices do not lock up under heavy load.
[00:15:15] TCP session and connection throttling
Managing TCP sessions correctly prevents stateful firewalls and local network stacks from getting overwhelmed during a scan.
- Global max TCP sessions: Caps simultaneous connections to ensure stateful firewalls and NAT routers do not exhaust their state tables and drop legitimate business traffic.
- Max TCP sessions per host: Controls the packet transmission rate of the SYN scanner, which is crucial for protecting sensitive network appliances from packet density overloads.
[00:17:58] Engine threading and execution limits
Engine threading parameters balance execution speed with system load by scaling worker threads across your CPU processors.
- Max engine checks and threads: Dictates how many parallel scan engines spawn, scaling across your host CPU to maximize multi-core execution speed.
- Plugin timeout: Defines the maximum lifetime a plugin script or socket connection runs. Adjusting this can dramatically accelerate scans on a clean, low-latency local area network.
[00:22:04] Policy options and plugin families
Individual scan policies establish the execution parameters for a specific job, and understanding them prevents unnecessary manual overhead.
- Policy precedence: While global scanner settings dictate maximum capacity, your individual scan policy enforces the specific execution boundaries for a given job.
- Plugin family selection: Manually disabling unused plugin families yields virtually zero benefit in scan execution time, as the engine automatically discards irrelevant plugins after fingerprinting the target operating system.
[00:25:26] Host discovery and pinging methods
Configuring host discovery correctly ensures you only spend time scanning active assets while bypassing unnecessary network checks.
- Host discovery settings: Turning off the ping remote host feature eliminates discovery overhead if your target list consists strictly of confirmed active IP addresses, but it slows down scans if offline addresses are included.
- Pinging methods: On a local area network, relying on ARP ping instead of TCP or ICMP significantly speeds up host discovery.
- Fragile devices: Built-in safeguards automatically identify fragile endpoints like printers and OT hardware to halt scanning against them. For dedicated OT asset visibility, we recommend using Tenable OT Security.
[00:29:36] Port scanning and local enumerators
Choosing the right port scanning techniques balances scan thoroughness with minimal network noise.
- Port scan range: By default, the engine scans approximately 4,700 commonly used ports. Setting this to all ports increases thoroughness but extends execution time.
- Local port enumerators: Using valid administrative credentials to run local commands is fast, accurate, and generates minimal network traffic.
- SYN stealth scan: A TCP SYN stealth scan completes faster than a full TCP scan because it only requires two packet exchanges instead of a full three-way handshake.
[00:33:21] Assessment settings and thorough tests
These assessment options control the depth of your vulnerability checks and how user data is enumerated during credentialed scans.
- Perform thorough tests: Enabling this allows plugins to perform exhaustive file system and registry searches, increasing finding depth but generating heavy target CPU load.
- User enumeration: In large Active Directory environments, unchecking user enumeration methods drastically speeds up Windows credentialed scans if account auditing is not required.
[00:36:35] Advanced general settings and performance options
Advanced policy options provide crucial safeguards for network bandwidth and scanner efficiency.
- Safe checks: Keep this enabled in production environments to prevent plugins from executing dangerous payloads that could crash live services.
- Network congestion detection: Enabling this prompts the engine to monitor latency spikes and throttle packet transmission automatically until congestion subsides.
- Network timeout adjustments: Reducing the default timeout on a fast local network decreases total scan duration, while reusing SSH connections eliminates authentication overhead on target security logs.
[00:40:35] Question and answer session
We conclude with an interactive question and answer session addressing specific use cases, configurations, and licensing capabilities.
- Basic vs. advanced scans: You can customize performance settings within standard templates like the basic network scan, which we recommend using to set a baseline before tailoring advanced policies.
- Web application scanning: For dynamic application security testing, we recommend using Tenable Nessus Expert, which includes dedicated web application scanning capabilities.
- Monitoring scanner health: You can monitor your scanner's CPU usage, memory history, and network traffic directly from the scanner health settings in your console.
Tenable One
Solicite una demostración
La plataforma de gestión de exposición con tecnología de IA líder en el mundo.
Gracias
Gracias por su interés en Tenable One.
Un representante se pondrá en contacto con usted en breve.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success