Port Exclusions

For a network scan, AppViewX lets you create a list of port sources that have to be excluded from the scans. This list is called an exclusion list and it is made of IP addresses and/or subnets that have to be excluded from a network discovery scan. Exclusion lists are different from rules; while rules let you exclude port addresses after a discovery operation is completed, an exclusion list will do the same thing but before the discovery operation is triggered.

Creating an Exclusion List

  1. Go to (Menu) > CERT+ > CERTIFICATE DISCOVERY > Discovery Configuration > Excluded Ports.
    The Excluded Ports page is displayed.
  2. Click + Create.
    The Add page is displayed.
  3. Enter/Select the exclusion list details.
    Important: Maximum of 5000 exclusion list is allowed.
    Table 1. Field descriptions for the exclusion list details
    Field Description
    *Excluded Ports Name Enter a name for the exclusion list.
    Important: This field does not support special characters.
    Description Add a short description with the reason to be excluded.
    Network Setting Select a network setting to enforce this excluded network across all associated networks. The available options are:
    • All
    • Custom.
    *Select Settings Select the network settings that applies to this entry.
    Note: This field appears when Network Setting = Custom.
    *Exclusion By From the dropdown list, from the following options, select the source of the exclusion list:
    • Custom: Lets you enter a list of the Port addresses and/or subnets to be excluded from the network scan.
    • Upload: Lets you upload a file that has the IP addresses and/or subnets to be excluded from the network scan

      Acceptable file formats: .xlsx, .xls, .csv

      Important: To view a sample exclusion list file:
      1. From this dropdown list, select Upload.

        The Upload File field is displayed.

      2. From below the Upload File field, click Download Sample Template.

        The sample template will be downloaded to your system.

    *Excluded Ports This field is displayed if Exclusion By = Custom.

    Enter a valid port numbers between 1 to 65535.

    *Browse This field is displayed if Exclusion By = Upload.
    To upload a .xlsx/.xls/.csv file that has the exclusion list:
    1. Click Upload.
    2. Navigate to the location of the file.
    3. Select the required file.
    4. Click Open.
    Important: To view a sample exclusion list file:
    1. From below the Upload File field, click Download Sample Template.

      The sample template will be downloaded to your system.

    *: Mandatory fields
  4. Click Add.
    The table below the fields is populated with entries from the Exclusion List/file uploaded with the exclusion list.
  5. Click Save.

Disabling an Exclusion List

By default, exclusion lists are enabled as soon as they are created. Which means that when a network discovery operation is triggered, the results will exclude all the network sources that are a part of the exclusion lists. You can choose to disable an execution list so that it is not considered for the subsequent network discovery scans.

Additionally, you can enable selected disabled exclusion lists for a specific scan at the time of configuring the scan, by selecting the required list(s) from the Exclusion Lists dropdown list.

To disable an exclusion list:

  1. Go to (Menu) > CERT+ > CERTIFICATE DISCOVERY > Discovery Configuration > Excluded Ports.
    The Excluded Ports page is displayed.
  2. From the exclusion list inventory, under Status, move the radio button to left that you want to disable.
    The confirmation dialog box appears as Excluded Port Successfully Disabled.

Enabling an Exclusion List

To enable an exclusion list after it has been disabled:

  1. Go to (Menu) > CERT+ > CERTIFICATE DISCOVERY > Discovery Configuration > Excluded Ports.
    The Excluded Ports page is displayed.
  2. From the exclusion list inventory, under Status, move the radio button to right that you want to Enable.
    The confirmation dialog box appears as Excluded Port Successfully Enabled.

Deleting an Execution List

  1. Go to (Menu) > CERT+ > CERTIFICATE DISCOVERY > Discovery Configuration > Excluded Ports.
    The Excluded Ports page is displayed.
  2. From the exclusion list inventory, under Excluded Ports, select the checkbox(es) corresponding to the exclusion list(s) you want to delete.
  3. From the menu bar, click .
  4. From the confirmation dialog box, click Submit.
    The selected exclusion list(s) are deleted.
    Note: Default ports cannot be deleted.