
Abellary042091 (Community Member) asked a question.
Hello,
We are currently facing an authentication issue (error code 403) during our dynamic analysis. It appears that our gateway is blocking the scan, preventing it from completing successfully.
Can anyone suggest a solution to resolve this issue? Specifically, we're looking for:
- IP Address Whitelisting: Are there any specific IP addresses we need to whitelist to allow the scan to bypass the gateway restrictions?
- Gateway Configuration Adjustments: Is there a particular configuration or setting within the gateway that we should adjust to prevent the 403 error from being triggered?
We would greatly appreciate any insights or step-by-step guidance to resolve this.
Thank you for your support!
.png)
hello @Abellary042091 (Community Member)
You'll need to review any securty layer that protects your environment and applications (Firewall, WAF, IPS, IDS, Proxy) to allow inbound the DAST IP addresses.
Here you can see the public IPs used by Veracode DAST -> https://docs.veracode.com/r/IP_addresses#veracode-dynamic-analysis
https://docs.veracode.com/r/IP_addresses#veracode-dast-essentials
If you have applications not Iternet facing, you'll need to use ISM endpoint
https://docs.veracode.com/r/c_using_ism
https://docs.veracode.com/r/c_system_requirements
After setting up this, you can add a new application to scan and start a prescan with Dynamic analysis to ensure that the scanner can reach and auth in your apps
https://docs.veracode.com/r/t_was_prescan