What is Vulnerability Scanning?

Vulnerability scanning is the process of identifying and assessing security weaknesses in a system or network. These weaknesses can be exploited by attackers to gain unauthorized access or cause damage. Vulnerability scanners automatically scan devices to detect outdated software, misconfigurations, or missing patches that could be leveraged by malicious actors.



Roqos Vulnerability Scanning


Roqos provides the community version of the OpenVAS vulnerability scanner integrated in Roqos SASE. It can run within your network while being remotely managed. You can automatically or manually scan your devices to identify security weaknesses—such as outdated software, misconfigurations, or missing patches—that could be exploited by attackers. Roqos SASE allows you to remotely and securely access all your multiple OpenVAS instances from a single UI to monitor your entire network for ultimate productivity.


Distributed OpenVAS


Roqos delivers a distributed OpenVAS architecture, enabling secure, remote visibility across your entire network from a unified dashboard. Easily scan your networks in branch offices, public or private clouds, and main headquarters in a few clicks. All scan data stays on your local Roqos Cores and is never transmitted to the Roqos Cloud, ensuring total data privacy.

Flexible Deployment Modes: Inline vs. Stand-Alone


In Inline Mode, the Roqos Core appliance resides directly within the active data path of your network infrastructure. Operating inline allows the integrated OpenVAS vulnerability scanner to conduct direct, security audits across connected subnets, local endpoints, and gateway boundaries. By initiating active vulnerability probes and port scans straight from the live network path, OpenVAS can comprehensively evaluate network assets, identify exposed services, and detect misconfigurations exactly as an external or internal attacker would encounter them.

In Stand-alone Mode, the Roqos Core appliance does not act as the primary router or gateway for the network. Instead, it operates independently alongside your existing network infrastructure—connected via a dedicated port. In this configuration, OpenVAS operates as an stand-alone vulnerability scanner, leveraging the Roqos Core’s network interface to independently reach out and audit any IP range, subnet, or VLAN accessible to it across your existing routing environment.

REQUEST DEMO