2-52
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Data Enabling Features
Configuring Network Admission Control Features
Network Admission Control (NAC) is a Cisco Systems sponsored industry initiative that uses the
network infrastructure to enforce security policy compliance on all devices seeking to access network
computing resources, thereby limiting damage from viruses and worms.
Using NAC, organizations can provide network access to endpoint devices such as PCs, PDAs, and
servers that are verified to be fully compliant with established security policy. NAC can also identify
noncompliant devices and deny them access, place them in a quarantined area, or give them restricted
access to computing resources.
MARS supports the NAC initiative by storing and reporting about the NAC-based events generated by
the various reporting devices on your network. The devices include:.
•
Cisco Trust Agent. While CTA does not report to MARS, it does report discovered settings to the
Cisco network devices, from which MARS collects events.
•
3rd-party 802.1x Supplicants.
•
Cisco IOS routers running Cisco IOS Software, Release 12.3(8)T with security.
•
Cisco VPN 3000 Concentrators
Cisco ASA 7.0
DEVICE_RES_OID_CPU
.1.3.6.1.4.1.9.9.109.1.1.1.1.3.1
DEVICE_RES_OID_MEMORY_FREE
.1.3.6.1.4.1.9.9.48.1.1.1.6.1
DEVICE_RES_OID_MEMORY_USED
.1.3.6.1.4.1.9.9.48.1.1.1.5.1
DEVICE_RES_OID_CONNECTION
.1.3.6.1.4.1.9.9.147.1.2.2.2.1.5.40.6
DEVICE_RES_OID_INTERFACE_NUMBER
.1.3.6.1.2.1.2.1.0
DEVICE_RES_OID_INTERFACE_IN_BYTES
.1.3.6.1.2.1.2.2.1.10.i
DEVICE_RES_OID_INTERFACE_OUT_BYTES
.1.3.6.1.2.1.2.2.1.16.i
DEVICE_RES_OID_INTERFACE_IN_BANDWIDTH
.1.3.6.1.2.1.2.2.1.5.i
DEVICE_RES_OID_INTERFACE_OUT_BANDWIDTH
.1.3.6.1.2.1.2.2.1.5.i
DEVICE_RES_OID_INTERFACE_IN_ERROR
.1.3.6.1.2.1.2.2.1.14.i
DEVICE_RES_OID_INTERFACE_OUT_ERROR
.1.3.6.1.2.1.2.2.1.20.i
DEVICE_RES_OID_INTERFACE_IN_UCAST_PACKET
.1.3.6.1.2.1.2.2.1.11.i
DEVICE_RES_OID_INTERFACE_IN_NUCAST_PACKET
.1.3.6.1.2.1.2.2.1.12.i
DEVICE_RES_OID_INTERFACE_OUT_UCAST_PACKET
.1.3.6.1.2.1.2.2.1.17.i
DEVICE_RES_OID_INTERFACE_OUT_NUCAST_PACKET
.1.3.6.1.2.1.2.2.1.18.i
DEVICE_RES_OID_INTERFACE_DESCRIPTOR
.1.3.6.1.2.1.2.2.1.2.i
DEVICE_RES_OID_INTERFACE_IN_DISCARDS
.1.3.6.1.2.1.2.2.1.13.i
DEVICE_RES_OID_INTERFACE_IN_UNKNOWN_PROTOS
.1.3.6.1.2.1.2.2.1.15.i
DEVICE_RES_OID_INTERFACE_OUT_DISCARDS
.1.3.6.1.2.1.2.2.1.19.i
CheckPoint OpSec
NG FP3
DEVICE_RES_OID_CONNECTION
.1.3.6.1.4.1.2620.1.1.25.3.0
DEVICE_RES_OID_INTERFACE_NUMBER
.1.3.6.1.2.1.2.1.0
Table 2-5
SNMP OIDs Required for Resource Monitoring (continued)
Vendor, Model,
and Version
OID Descriptor
OID