3-9
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 3 Configuring Router and Switch Devices
Cisco Switch Devices
Result
: The submit operation records the changes in the database tables. However, it does not load the
changes into working memory of the MARS Appliance. The activate operation loads submitted changes
into working memory.
Step 12
Click
Activate
.
Result
: MARS begins to sessionize events generated by this device and evaluate those events using the
defined inspection and drop rules. Any events published by the device to MARS before activation can
be queried using the reporting IP address of the device as a match criterion. For more information on the
activate action, see
Activate the Reporting and Mitigation Devices, page 2-27
.
Cisco Switch Devices
You can manage Cisco switches that run either CatOS or Cisco IOS Software Release 12.2 or later. The
configuration of the switch varies between these two operating system, as does the addition of the device
in MARS. Adding a Cisco switch involves three steps:
1.
Configure the switch to enable MARS to discover the its settings.
2.
Configure the switch to generate the data required by MARS.
3.
Add and configure the switch in MARS.
4.
Add modules to the switch.
To prepare a Cisco switch running Cisco IOS Software Release 12.2 or later, refer to the following
procedures:
•
Enable Administrative Access to Devices Running Cisco IOS 12.2, page 3-1
•
Configure the Device Running Cisco IOS 12.2 to Generate Required Data, page 3-3
To prepare a Cisco switch running CatOS, refer to the following procedures:
•
Enable Communications Between Devices Running CatOS and MARS, page 3-9
•
Configure the Device Running CatOS to Generate Required Data, page 3-11
Adding a Cisco switch running to MARS has two distinct steps. First, you add the base module of the
switch, providing administrative access to that device. Second, you add any modules that are running in
the switch. For instructions on performing these two steps, refer to the following topics:
•
Add and Configure a Cisco Switch in MARS, page 3-13
•
Adding Modules to a Cisco Switch, page 3-14
Enable Communications Between Devices Running CatOS and MARS
Before you add a Cisco switch running CatOS to MARS, make sure that you have enabled SNMP, Telnet,
SSH, or FTP access to the swtich. First, you must configure the MARS Appliance as an IP address that
is permited to access the switch.
For information on permitting IP addresses and specifying the access type, see the following URL:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_8_4/confg_gd/ip_perm.htm#wp101
9819
Next, you must ensure that your switch is configured to enable the correct access method. The following
sections provide guidance on configuring each supported access method: