
WAF Blocking EASM Scanning: Should the IP Range Be Whitelisted?
CybersecurityNetwork SecurityVulnerability ScanningWAF Management
The author's organization uses a cloud-based EASM in SaaS that performs continuous 24X7 scans to discover unknown external assets and vulnerabilities. However, the on-premises perimeter WAF is blocking this incoming scan traffic. The author is considering suggesting the whitelisting of the /24 IP range used by the EASM for these continuous scans but wonders if this would negate the purpose of the perimeter WAF rules.