
Copyright © 2002-2012 Tenable Network Security, Inc.
hosts. To prevent rediscovery of the entire network, the PVS
can frequently write the list of active hosts to a file so that
the information is available to PVS across restarts. Tenable
recommends that this file be updated every 120 minutes.
The location on the disk to save the backup file.
Specifies the networks to be monitored. This is set by the
PVS installation script in Unix.
Specifies any networks that should be excluded from PVS
monitoring. Networks should be specified using CIDR
notation and placed between the brackets after this directive.
If left blank, no addresses will be excluded.
Specifying Focus Networks
The “networks” keyword is used to indicate which networks the PVS will focus on while
performing passive vulnerability analysis. While the PVS runs, it evaluates a network session
only if one of the IP addresses is within a list of specific networks. These networks are
known to the PVS as the “focus networks”. Without the specification of a list of networks for
the PVS to monitor, it will monitor the entire Internet and report not only on your
vulnerabilities, but on the vulnerabilities of systems communicating with your network.
Tenable recommends configuring your PVS to focus only on networks you are responsible
for.
The “networks” keyword can specify hosts or networks using CIDR notation. Here are
several examples of valid entries:
> 10.10.10.22
> 10.10.10.22/32
> 10.10.10.0/24
> 10.163.155.0/255.255.255.0
> 0.0.0.0/0
The last example is used to conduct passive vulnerability analysis on every network session
and host observed. For busy networks with large numbers of unique visitors and active IP
addresses, the PVS will consume large amounts of memory and produce very large reports.
Care should be used when monitoring an active network without a specific focus address.
Tenable has deployed PVS sensors in front of popular web sites and performed
passive vulnerability analysis on more than 75,000 unique IP addresses at one
time. The PVS is much more efficient if it is focused on one particular range of
addresses.
Using Multiple Interfaces
The PVS can use multiple interfaces. To specify this, simply use multiple lines to specify
multiple interfaces. For example, the pvs.conf file shown below will cause the PVS to look
at both the eth0 and eth1 interfaces:
Comentários a estes Manuais