# Vulnerability Management WAN Architecture ManageEngine Vulnerability Manager Plus is an Enterprise [vulnerability management](https://www.manageengine.com/vulnerability-management/what-is-vulnerability-management.html) software that helps you scan, assess, prioritize and remediate vulnerabilities in your network endpoints. It comprises features like [vulnerability scanner](https://www.manageengine.com/vulnerability-management/vulnerability-scanner.html) and [vulnerability assessment](https://www.manageengine.com/vulnerability-management/vulnerability-assessment.html), automated patch management, [security configuration management](https://www.manageengine.com/vulnerability-management/security-configuration-management.html), [zero-day vulnerability mitigation](https://www.manageengine.com/vulnerability-management/zero-day-vulnerability-mitigation.html), high-risk software audit, and web server hardening. Vulnerability Manager Plus supports the patching of computers in a distributed setup like branch or remote offices (WAN) and for mobile users, for example, sales personnel who are constantly on the move. ## Advantages The advantages of using the WAN architecture of Vulnerability Manager Plus include the following: 1. Affordable, simple, and quick solution for vulnerability management requirements 2. Utilizes low bandwidth 3. Enables network-neutral patch management 4. Utilizes the same infrastructure for VPN connections. No separate VPN infrastructure is required 5. Ensures that communication between the server and agents is secured 6. Patches computers centrally using a single Web console The following guide will help you understand the process of vulnerability management with the help of an architecture diagram. ![vulnerability-management-wan-architecture](https://www.manageengine.com/vulnerability-management/images/vmp-architecture-wan-updated.png) IT administrators or network security teams need the following components to perform vulnerability management in remote computers: 1. [Vulnerability Manager Plus Server](#vulnerability-manager-plus-server) 2. [Distribution Server](#distribution-server) 3. [Agents](#agents) 4. [Web Console](#web-console) ## Vulnerability Manager Plus Server The Vulnerability Manager Plus Server helps you centrally perform all vulnerability management tasks in your network endpoints. Some of the tasks include the following: - Installing agents in computers - Scanning computers for vulnerabilities and misconfigurations - Deploying patches and secure configurations - Uninstalling high-risk software Any Windows computer in your network with the requirements mentioned [here](https://www.manageengine.com/vulnerability-management/system-requirements.html) can be hosted as your Vulnerability Manager Plus Server. This server at the customer site subscribes to the Central Vulnerability Database, from which it synchronizes the latest information on vulnerabilities and their remedies. Patches are downloaded directly from vendor sites and stored centrally in the server's patch store, and will be replicated to your network endpoints to conserve bandwidth. ## Components This section includes detailed information about the components of the Vulnerability Manager Plus architecture. ### Server Ports | Port | Purpose | Type | Connection | |---|---|---|---| | 8020 | Agent Server communication | HTTP | Inbound to server | | 8027 | Agent Server communication | TCP | Inbound to server | | 8022 | To enable Chat and System Manager | HTTP | Inbound to server | | 8383 | Communication between agent/distribution server and VMP Server | HTTPS | Inbound to server | | 135 | Remote admin, file/printer sharing | TCP | Outbound from managed computers | | 445 | File/printer sharing | TCP | Outbound from managed computers | | 8443 | Patch download progress display | HTTPS/HTTP | Inbound to server | ### Active Directory Ports | Port | Purpose | Type | Connection | |---|---|---|---| | 636 | LDAP over SSL | TCP | Outbound from Server | | 389 | LDAP | TCP, UDP | Outbound from server | **Note:** Ports 135, 139, and 445 should also be kept open and inbound on both agent and server (and distribution server, if applicable) for pushing agent installation. Vulnerability Manager Plus Server has to be installed in your LAN (for example, the head office) and configured as an EDGE device. This means that the designated port (default being 6020 and configurable) should be accessible through the Internet. You need to adopt necessary security standards to harden the OS where the Vulnerability Manager Plus Server is installed. Agents from all remote locations report to this server. The server acts as a container to store patch details and, upon request, provide instructions to the agents. It is advised to keep the Vulnerability Manager Plus Server always running to carry out day-to-day vulnerability management activities. ## Distribution Server Distribution Server is lightweight software that is installed on one of the computers in the branch offices. This agent communicates with the Vulnerability Manager Plus Server to pull information for all computers in that branch. The agents residing in branch office computers contact the Distribution Server to get the available information and process requests. - Low bandwidth utilization as only one agent contacts the server periodically - Pulls patches to be installed and other related details from the Vulnerability Manager Plus Server and makes them available for the rest of the computers in the branch - Supports secured mode of communication (SSL/HTTPS) with the server - Distribution Server installation is a one-time task and subsequent upgrades are performed automatically ## Agents To perform vulnerability scanning and management, a lightweight, multipurpose agent is installed by the server on your network systems. The agent contacts the server every 90 minutes to get data to perform vulnerability scanning on endpoints as well as to carry out tasks delegated by the server. It returns the results to the server after completing the task. The agent also maintains a continuous thin connection with the server to perform on-demand tasks. Agents can be installed either manually or using a logon script on all branch-office computers that are managed using Vulnerability Manager Plus. This is a one-time task. Agent upgrades are performed automatically. Vulnerability Manager Plus offers two options to help administrators manage computers across a WAN. The option you choose depends on the number of computers you manage at your remote office: 1. **Distribution servers and WAN agents:** Recommended if you are patching more than 10 computers in a remote office. 2. **WAN agents only:** Recommended if you are patching fewer than 10 computers in a remote office. ## Web Console The web console is a graphical user interface used to access the server and perform vulnerability management tasks. This console can be accessed from anywhere—for example, through a LAN, WAN, or from home using the Internet or a VPN. Separate client installations are not required to access the web console.