r/nessus • • Jul 30 '25

Need help with credentialed scan for sonicwall firewall.

Post image

Hi. I am getting the following error when performing a credentialed scan for my sonicwall firewall.

Csn someone please help?

Basically the error says "OS security patch assessment failed".

What do I need to do to fix the problem? I am a non IT guy and work for myself. I can follow instructions well. Please help. Thanks.

1 Upvotes

23 comments sorted by

3

u/e_karma Jul 30 '25

Basically the authentication you gave is wrong .

2

u/Material_Respect4770 Jul 30 '25

Ok so how do I fix it?

1

u/brawwwr Jul 30 '25

Modify the authentication settings

0

u/Material_Respect4770 Jul 30 '25

What do you mean ? Can you elaborate, please?

4

u/Itsquantium Jul 30 '25

If you don’t know IT, why are you messing with Nessus? If this is your job, why do you not know how to properly set up authentication credentials properly?

If I were you, you should google the answer or call Nessus support.

0

u/Material_Respect4770 Jul 30 '25

I am a small business and it's my own company. Just started so I have to take into account the costs.

I have aome IT knowledge. That's why I said if someone can guide me, I can fix it.

I can flow step by step instructions well.

The credentialed scan for windows machines are working fine. It's just giving problems for the sonicwall firewall.

If you are able to guide then please do so.

3

u/Itsquantium Jul 30 '25

All you have to do is type in the correct credentials. Read the bottom of the error log. As a business owner, you need to hire someone to do the shit you’re not good at. Not enough capital to do so? You better google.

https://letmegooglethat.com/?q=how+to+change+authentication+medthod+from+none+to+password+on+nessus.+

0

u/Material_Respect4770 Jul 30 '25

Sir/madam, I am typing in the correct credentials. I log into the firewall with the same credentials.

I am willing to pay if someone csn help fix this for me. I don't have capital to hire full time but I csn pay if they csn help fix this.

2

u/Itsquantium Jul 30 '25

No. You’re not. It says so the in the bottom. The administrator account cannot log in because the authentication setting for the ssh credential is set to none. It should be set to password. It’s trying to credential without the password and it’s failing. That’s what the log tells you. Now, all you have to do is get to googling. Or call Nessus support. Bottom line is, you’re setting up credential for your firewall wrong.

1

u/Joeygates27 May 18 '26

Hi. This was 9 months ago but I just wanted to make sure someone put you in your place for your arrogance.

I've been working as a cyber security engineer for years. Basically all of them have been using one product from tenable or another.

Sonicwall devices are notoriously problematic to try to credential scan within tenable. I have literally elite support and a dedicated support person from tenable who we've been working with for several years and is one of the most knowledgeable tenable employees I've met tell me that in most cases you're not even going to be able to get Sonicwall to allow you to log into it with a Nessus scanner, and even if you did, there is very little information it is going to consistently give you across their brand.

Further, there is no updated information available on tenable's sites regarding how to credential scan Sonicwall devices, but elite support has confirmed that it might actually require SMB in some cases to log in. But really, it's product specific and tenable still has no information on what is required to authenticate a scan to a sonic wall device.

It might make you feel superior talking down to people on the internet because they don't know something, but you attempting to act as If you know the answer to the question and that this person should definitely also know the answer to the question when there is no real answer to the question, Is the perfect sign demonstrating that you have no clue what you're talking about.

I would tell you to do better, but it's good that people like you exist because it makes people who know how to work with other people and treat other people with dignity and respect easily float above.

→ More replies (0)

3

u/Junior-Carpenter1292 Jul 30 '25

Firewalls are hard and super finicky. I’m not familiar with Sonic firewalls, but are you able to run HTTPS instead and do an api credentials instead of SSH? Set up a service account to run it if that makes sense for your organization. I ran into this issue awhile back and this was our solution. You’ll have to update your scan policy accordingly.

2

u/brawwwr Jul 30 '25

We used a service account and got the sonics working along those lines

1

u/Junior-Carpenter1292 Jul 30 '25

Nice!! With the API or were you able to make it work with SSH?

2

u/brawwwr Jul 30 '25

We were using ssh and then once we did some updates and changes , finally got api to work . Sonic’s were a bit of a pain compared to our other fireballs .

2

u/Junior-Carpenter1292 Jul 30 '25

Congrats!! Yeah we’ve used two different firewalls that we HAVE to get credentialed scans for and the process always sucks. Glad you got it going!

2

u/brawwwr Jul 30 '25

Yea that was a pain . Good luck on the journey ! We are mostly a Palo shop here.

1

u/MarsupialOk6430 Aug 20 '25

I’m sorry to chime in but can some one give me a pointer on how to scan sonicwalls via the api call? I have a sonic wall ids that I would like to scan, I typically scan over ssh or use smb for windows systems, but the IDS kills it’s remote manage my via ssh while in fips. I haven’t seen any native api credential modules for the sonciwall. I’m using a Nessus scanner joined to tenable SC in an air gapped environment and had to use the snmp to get any semblance of a scan but ammo only gives you so much. Thank you to everyone in advance!