Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Adding a McAfee Vulnerability Manager SOAP API Scan

 

You can add a McAfee Vulnerability Manager scanner to enable JSA to collect host and vulnerability information through the McAfee OpenAPI.

  1. Click the Admin tab.
  2. Click the VA Scanners icon.
  3. Click Add.
  4. In the Scanner Name field, type a name to identify the scanner.
  5. From the Managed Host list, select the managed host that manages the scanner import.

    Certificates for the scanner must be on the managed host that is selected in the Managed Host list.

  6. From the Type list, select McAfee Vulnerability Manager.
  7. In the SOAP API URL field, type the IP address or hostname of the McAfee Vulnerability Manager that contains the vulnerabilities you want to retrieve with the SOAP API.

    For example, https://foundstone IP address:SOAP port. The default value is https://localhost:3800.

  8. In the Customer Name field, type the name of the customer that belongs to the user name.
  9. In the User Name field, type the user name to access McAfee Vulnerability Manager.
  10. In the Client IP Address field, type the IP address of the server that you want to perform the scan.Tip

    This field is typically not used; however, it may be required for you to validate some scan environments.

  11. In the Password field, type the password to access McAfee Vulnerability Manager.
  12. In the Configuration Name field, type the scan configuration name that exists in McAfee Vulnerability Manager and to which the user has access.

    Make sure that this scan configuration is active or runs frequently.

  13. In the CA Truststore field, type the directory path and filename for the CA truststore file.

    The default path is /opt/qradar/conf/mvm.keystore.

  14. In the CA Keystore field, type the directory path and filename for the client keystore.

    The default path is /opt/qradar/conf/mvm.truststore.

  15. From the McAfee Vulnerability Manager Version list, select the software version of your McAfee Vulnerability Manager.
  16. To remove previously detected vulnerabilities that were not detected by the most recent scan, select the Vulnerability Cleanup check box.
  17. To configure a CIDR range for the scanner:
    1. Type the CIDR range for the scan or click Browse to select a CIDR range from the network list.

      The McAfee Vulnerability Manager accepts only CIDR addresses ranges to a 0/0 subnet that are added as 0.0.0.0/0.

    2. Click Add.

  18. Click Save.
  19. On the Admin tab, click Deploy Changes.

You are now ready to create certificates from McAfee Vulnerability Manager. See Creating Certificates for McAfee Vulnerability Manager.