Archived community.zenoss.org | full text search
Skip navigation
5624 Views 4 Replies Latest reply: Dec 8, 2011 10:15 AM by Davian RSS
Davian Newbie 3 posts since
Dec 3, 2011
Currently Being Moderated

Dec 7, 2011 9:48 AM

Zenoss + Nessus Scan = Alert Explosion

I ran into an interesting problem the other day.  I scanned my internal network using Nessus and when the scanner hit my Zenoss machines, they alerted like crazy.  The Zenoss servers reported every single one of the monitored servers as down, they couldn't poll for data at all.  Once the scan finished, the Zenoss servers came back to normal like nothing ever happened.  I can't fathom why a vulnerability scan would cause Zenoss to freak out like that.  I was running the scan in safe-mode so it shouldn't have used any plugins that would break anything.  There's absolutely nothing out of the ordinary in the logs, as far as I can see.  Any ideas?  Has anyone seen this before?

  • Chet Luther ZenossEmployee 1,302 posts since
    May 22, 2007
    Currently Being Moderated
    2. Dec 7, 2011 10:07 AM (in response to Davian)
    Re: Zenoss + Nessus Scan = Alert Explosion

    That's an odd one. Can't say I've seen anything like that before.

     

    What kinds of devices are the monitored systems? Linux servers, Windows servers, networking equipment? My first guess would be that Nessus is saturating some resource on them like throughput or state tables (for firewalls.) My next guess would be that they have some kind of security feature that is shutting down communication in response to the Nessus scan. It might be useful to check their logs.

  • jmp242 ZenossMaster 4,060 posts since
    Mar 7, 2007
    Currently Being Moderated
    3. Dec 7, 2011 10:08 AM (in response to Davian)
    Re: Zenoss + Nessus Scan = Alert Explosion

    It sounds like saturation of the remote devices, or theres some security software on them that is shutting down access during the scan. Per cluther...

     

    --

    James Pulver

    ZCA Member

    LEPP Computer Group

    Cornell University

More Like This

  • Retrieving data ...

Legend

  • Correct Answers - 4 points
  • Helpful Answers - 2 points