Install a vScanner using the Azure portal
As part of Arctic Wolf® Managed Risk, install a Virtual Scanner (vScanner) to perform continuous risk monitoring and vulnerability assessments.
Note:
- These steps only apply if you have a plan other than a Cloud Solution Provider (CSP) plan. If you have a CSP plan, see Install a vScanner using the Azure portal with a CSP plan.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Microsoft Defender for Cloud Apps® flags vScanners as containing malware because vScanners contain code that is used to detect vulnerabilities. To avoid this behavior, create a suppression rule to exclude the vScanner from Microsoft Defender for Cloud Apps monitoring. For more information, see Create a suppression rule.
- Schedule host identification and vulnerability scans. For more information, see Configure a scanner.
Provide your Azure account information to Arctic Wolf
Create a vScanner instance
Connect to the serial console
In the left navigation, click Serial console.
Configure the vScanner
Use the serial console to configure the vScanner. For more information on using the serial console, see Serial console.
Activate the vScanner
Note: Only the user who configured the vScanner can activate the vScanner.