3-14
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 3 Configuring Router and Switch Devices
Cisco Switch Devices
Step 9
(Optional) If you defined an access IP and selected and configured an access type, click
Discover
to
determine the device settings
Result
: If the username and password are correct and the MARS Appliance is configured as an
administrative host for the device, the “Discovery is done.” dialog box appears when the discovery
operation completes. Otherwise, an error message appears. After the initial pull, the MARS Appliance
pulls based on the schedule that you define. For more information, see
Scheduling Topology Updates,
page 2-39
.
Step 10
To add this device to the MARS database, click
Submit
.
Result
: The submit operation records the changes in the database tables. However, it does not load the
changes into working memory of the MARS Appliance. The activate operation loads submitted changes
into working memory.
Step 11
Click
Activate
.
Result
: MARS begins to sessionize events generated by this device and evaluate those events using the
defined inspection and drop rules. Any events published by the device to MARS before activation can
be queried using the reporting IP address of the device as a match criterion. For more information on the
activate action, see
Activate the Reporting and Mitigation Devices, page 2-27
.
After submitting, you can add modules. See
Adding Modules to a Cisco Switch, page 3-14
.
Adding Modules to a Cisco Switch
In MARS, you can represent, discover, and monitor modules that are installed in Cisco switches. These
modules perform special purpose security functions for the switch, such as firewall or intrusion detection
and prevention. MARS recognizes the following switch modules and versions:
•
Cisco FWSM 1.1, 2.2, and 2.3
•
Cisco IDS 3.1 and 4.0
•
Cisco IPS 5.x
•
Cisco IOS 12.2
To add a module, you must first add the base module, which is the Cisco switch. After the base module
is defined in the web interface, you can discover the modules that are installed in the switch (click
Add
Available Module
) or add them manually (click
Add Module
).
For instructions on adding and configuring a firewall services module (FWSM), see
Cisco Firewall
Devices (PIX, ASA, and FWSM), page 4-1
.
For instructions on adding and configuring an intrusion detection or prevention services module (IDSM
or IPSM), see
Cisco IPS Modules, page 6-10
.
This section contains the following topics:
•
Add Available Modules, page 3-14
•
Add Cisco IOS 12.2 Modules Manually, page 3-15
Add Available Modules
When you perform a discovery operation on a base module, MARS lists the discovered modules. From
this list, you can select the modules to monitor using MARS.