skip to content

A scheduled Qualys scan of 10.20.0.0/16 fails with 'A virtual or physical scanner appliance is needed' — why, and what fixes it?

level: middleimportance: nice to knowfreq 12%

answer

  1. who scans from the internet
  2. private ranges need an inside sensor
  3. Default means different things per target
  4. Personalization Code and Online status
  5. API updates fall back silently

basics

~20 s

Qualys's external cloud scanners scan from the internet and will not scan private addresses. A 10.x target needs an internal scanner appliance, deployed where it can route to that range and selected for the scan.

solid answer

~40 s

Qualys has **external** scanners, run from its cloud for perimeter scans, and **internal** scanner appliances you deploy (virtual, physical, containerized or offline). External scanners do not scan private IPs (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and the listed 240.0.0.0 range). A scan aimed at them fails with exactly that error. To fix it, deploy an appliance inside the network. For a virtual one, add it under Scans > Appliances, enter the Personalization Code at first boot, and wait for status **Online**. Then pick it in the scan: by name, Build my list, All Scanners in TagSet, All Scanners in Asset Group, or All Scanners in Network. Beware "Default": with IP targets it means the external scanners. So does an API update to a scheduled scan that names no appliance.

go deeper

for a junior

Recall that Qualys's external scanners cover the internet-facing perimeter only, and that private addresses need a scanner appliance you deploy.

for a middle

Explain the appliance options (by name, Build my list, TagSet, Asset Group, Network, Default) and how Default resolves for IP targets versus asset groups.

for a senior

Show you would harden the schedules: an Online status and a Personalization Code per appliance, appliances grouped per network zone, and API automation that always names its appliance.

for a principal

Weigh where appliances live per zone, and how appliance pools and tags keep the scan estate maintainable as segments are added.

## External and internal scanning in Qualys When you launch or schedule a vulnerability scan in Qualys VMDR, you choose where the scan comes from: - **External**: Qualys's own cloud scanners (the Cloud Perimeter Scanner, also called the Internet Scanner). They need no deployment and assess your perimeter from the internet. - **Internal**: a **scanner appliance** you deploy. It can scan public and private IP addresses it can route to. The Qualys help on choosing a scanner appliance is explicit: external scanners do not scan private IPs. Asked to, the scan fails with: > A virtual or physical scanner appliance is needed to scan an IP address within your internal network. Please enter a non-internal IP or use a scanner appliance. The private ranges the help lists are 10.0.0.0-10.255.255.255, 172.16.0.0-172.31.255.255, 192.168.0.0-192.168.255.255 and 240.0.0.0-255.255.255.255. A target of 10.20.0.0/16 sits inside the first range, so nothing but an internal appliance can scan it. ## Appliance types | Type | What it is | |---|---| | Virtual Scanner | OVF/OVA image; minimum 2 vCPU, 4 GB RAM, 20 GB disk | | Physical Scanner | Rackmount hardware for high-volume on-premises scanning | | QCSA | Qualys Containerized Scanner | | Offline Scanner | Listed among the appliance types in the onboarding guide | | Cloud Perimeter Scanner | Qualys-hosted external scanner; no deployment | ## Fixing the scan 1. **Register an appliance.** Go to Scans > Appliances > Add New Appliance and generate a **Personalization Code**. 2. **Deploy it where it can route to the target.** Download the virtual image, deploy it, and give it a static IP on the management VLAN. The onboarding guide recommends grouping appliances by network zone, such as DMZ, Corporate LAN or Data Center. Why scanning through a firewall distorts results is a general scan-programme concern; here the point is only that the appliance must reach 10.20.0.0/16. 3. **Activate it.** Power it on, enter the Personalization Code, and wait until Scans > Appliances shows it **Online**. Initial activation can take up to 10 minutes. 4. **Select it in the scan.** The Scanner Appliance option appears only once your account has appliances. Without any, scans use the external scanners automatically. ## Choosing appliances for a scan - **A single appliance by name.** - **Build my list**: one or more appliances that share the scan job. - **All Scanners in TagSet**: appliances chosen by tag. Tag the appliances, then use IP Network Range tags as the scan target. - **All Scanners in Asset Group**: a pool of appliances defined for each target asset group. - **All Scanners in Network**: every appliance in the network you selected. - **Default**: with asset groups as the target, each group's default appliance. With IP addresses as the target, Qualys's external cloud scanners. That last row explains many broken schedules. A scan that targets a raw 10.x range with "Default" goes external, and fails. ## The API trap The same help page warns that if an API call updates a scheduled scan without naming a scanner appliance, Qualys uses an external scanner by default. If the target or asset group then mixes external and internal IPs, the scan errors. Automation that rewrites schedules has to set the appliance every time. Otherwise a scan that worked yesterday fails after a harmless-looking update. ## Mistakes that keep the error coming back - Deploying the appliance in a segment that cannot route to the target, so the scan launches but reaches nothing. - Leaving the schedule on Default with an IP-range target, which still resolves to the external scanners. - Mixing perimeter and internal addresses in one target. Split them into an external scan and an appliance scan. - Treating appliance registration as done before the status reads Online. ## After the fix Run the scan, then confirm it did what you meant. Check the scan results for the hosts reached. If the scan uses authentication records, check the Authentication Report under VM/VMDR > Reports > New > Authentication Report, or the Appendix of the scan results. They list hosts that passed authentication, failed it, or passed with insufficient privileges.

  • Your scan targets an asset group and the scanner option is Default. Which scanner runs it?
    The default scanner appliance defined for that asset group. Default resolves differently by target type: asset groups use their configured default appliance, while raw IP addresses use Qualys's external cloud scanners. Check the asset group's appliance setting before trusting a Default schedule.
  • A nightly job uses the Qualys API to update scheduled scans, and after a change, internal scans start failing. What do you look for?
    Whether the update names a scanner appliance. If an API call updating a scheduled scan omits it, Qualys defaults to an external scanner. Any target with internal IPs, or a mix of internal and external ones, then errors. Make the job set the appliance, or an appliance-selection option, explicitly on every update.

saying these in an interview costs you the question

  • Qualys's cloud scanners can reach private ranges through the internet
  • Default always means the asset group's default appliance
  • An appliance works as soon as the image boots
  • Omitting the appliance in an API update keeps the old choice
  • Mixed public and private targets are split between scanners automatically