- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Security Scan Tool source ips?
Hello, we have a firewall who bans ips and I think it banned Magento's security scan tool one. Does anyone know the source IP of this service to whitelist it?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Security Scan Tool source ips?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Security Scan Tool source ips?
It looks like the source IP is 52.87.98.44
The IDS I have on my server banned this IP each time I started a scan. Unfortunately the Magento Security Scan Tool spoofs the user-agent as Firefox, which is unhelpful for making exceptions for it.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Security Scan Tool source ips?
Hello,
Finally, have you been able to whitelist the Security Scan tool? I can't identify the IP nor the user-agent used to be whitelisted in our WAF, if I try with any domain outside the WAF it works... is a bit frustrating the lack of information.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Security Scan Tool source ips?
Hello,
You have here the information: https://support.magento.com/hc/en-us/articles/360029224131-The-Security-Scan-Tool-report-is-blank
At the moment it says:
Cause
This issue might appear because the Security Scan Tool was not able to reach your website. This means either the website is down and cannot be reached at all, or the Security Scan Tool is being blocked.
Solution
Try to open your web site.
- If the page loads successfully, you might need to add the IPs used by the Security Scan Tools to the firewall whitelist. The following IPs are used: 52.72.230.169, 52.87.98.44, 52.86.204.1, at ports 80 and 443.
- If the site doesn't load and returns the "There has been an error processing your request" message, check your website for possible errors.
Thanks,
Jose
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Security Scan Tool source ips?
Which is the file path to add the IPs?