ASM Network Configuration¶
Overview¶
Network configuration parameters control how ASM scans interact with target Assets from a network perspective, including request rate limits, request timeouts, and geographic scan origination. Proper network configuration is essential for balancing scan thoroughness against infrastructure impact, ensuring compliance with system constraints, and managing scan traffic across distributed environments.
This document covers two primary aspects of ASM network configuration: request rate limiting for scan traffic management, and Public Location configuration for geographic scan origination.
Request Rate Control¶
Use the network parameters in the Global Configuration to control ASM request rates. Choose a rate that fits your target infrastructure's capacity and security controls.
Configuration Parameters¶
The network parameters control request rate, timeouts, and custom headers:
requests_per_second
Maximum number of requests transmitted per second. This parameter establishes a hard rate limit, distributing requests over time to prevent burst traffic patterns. The range is 1 to 1000, with a schema default of 100. This setting also controls port scanner probes. It doesn't limit browser crawling.
request_timeout_s
Maximum duration (in seconds) for each individual request before timeout. This parameter prevents indefinite blocking on unresponsive endpoints.
custom_headers
Additional HTTP headers for scan traffic. See Custom Header Configuration.
Rate Limiting Configuration¶
The following configuration demonstrates rate control parameter usage with default values:
network:
requests_per_second: 100 # Default: 100 requests per second
request_timeout_s: 5 # Default: 5 second timeout per request
Configuration Behavior¶
Request Rate Behavior:
The requests_per_second parameter enforces a hard rate limit, spreading requests temporally to avoid burst patterns that may trigger rate-limiting controls or security alerts.
Performance Trade-offs:
- Lower parameter values reduce load on target infrastructure but increase total scan duration
- Higher parameter values accelerate scan completion but may trigger rate-limiting mechanisms or overwhelm service capacity
Use Cases for Rate Control¶
Production Environment Protection:
Use lower rate limits for production Assets to reduce scan traffic and its potential impact on end-user experience.
API Rate Limit Compliance:
Rate control parameters can be configured to remain within API provider rate limits or Web Application Firewall (WAF) thresholds, preventing scan interruption due to rate-based blocking.
Security Control Avoidance:
Request rates can be tuned to remain below thresholds that would trigger rate-limiting security controls, intrusion detection systems, or automated blocking mechanisms.
Infrastructure Capacity Management:
Balance scan speed against target infrastructure capacity and your availability and performance requirements.
Custom Header Configuration¶
Custom headers can be configured to identify and differentiate scan traffic from organic user traffic, enabling downstream systems to implement custom handling logic:
Custom headers are included in all requests transmitted during ASM scans, allowing WAFs, load balancers, or application logic to recognize and process scan traffic accordingly.
Complete network parameter documentation and advanced configuration options are available in the Configuration Reference.
Public Location Architecture¶
Public Locations define the geographic regions from which security scans originate. These locations are Organization-level resources that apply uniformly across all scan types.
Public Location Scope¶
You configure Public Locations at the Organization level. All enabled Public Locations are shared by ASM and DAST. Use Private Locations when a scan type or Asset needs its own geographic origin.
Current Architecture:
- Public Locations are Organization-level resources shared by all scan types
- Enabling or disabling Public Locations affects both DAST and ASM scans equally
- Use Private Locations for geographic control per scan type or Asset
Configure target firewalls to allow traffic from your enabled Public Locations. For IP allowlists and other requirements, see Firewall Configuration.
Geographic Restriction Requirements¶
If ASM and DAST need different geographic origins, configure Public Locations for ASM and deploy Private Locations in the regions required for DAST. For example, use US Public Locations for ASM when your firewall allowlist requires US origins, and a European Private Location for DAST when your testing requirements call for it.
Solution Approach¶
When geographic differentiation between ASM and DAST scans is required, the following approach must be implemented:
-
Public Location Configuration: Public Locations are configured to include only the regions required for ASM scans (for example, US Public Locations exclusively)
-
DAST Scan Migration: All DAST scans are migrated to use the same Public Locations configured for ASM requirements, or alternative connectivity methods are implemented
-
Private Location Deployment: If DAST scans require origination from regions not available in Public Location configuration, Private Locations are deployed in those specific regions as an alternative connectivity mechanism
This approach lets you choose scan origins to match your geographic restrictions.
Private Locations for Geographic Flexibility¶
For Organizations with complex geographic requirements or strict regional isolation mandates, Private Locations provide greater flexibility. Private Locations enable region-specific deployment while maintaining complete separation from Public Location configurations, allowing independent geographic control for different scan types or Assets.
Summary¶
Use request rate limits to manage scan traffic and Organization-level Public Locations to choose scan origins. Use Private Locations for geographic control per scan type or Asset. Match these settings to your infrastructure's capacity and network restrictions.