Contents
xiii
User Guide for Cisco Security MARS Local Controller
78-17020-01
C H A P T E R
18
Case Management
18-1
Case Management Overview
18-1
Case Management Considerations for the Global Controller
18-3
Hide and Display the Case Bar
18-3
Create a New Case
18-4
Edit and Change the Current Case
18-5
Add Data to a Case
18-6
Generate and Email a Case Report
18-7
C H A P T E R
19
Incident Investigation and Mitigation
19-1
Incidents Overview
19-1
The Incidents Page
19-2
Time ranges for Incidents
19-4
Incident Details Page
19-4
To Search for a Session ID or Incident ID
19-4
Incident Details Table
19-5
False Positive Confirmation
19-6
The False Positive Page
19-8
To Tune a False Positive
19-9
To Tune an Unconfirmed False Positive to False Positive
19-9
To Tune an Unconfirmed False Positive to True Positive
19-9
To Activate False Positive Drop Rules
19-10
Mitigation
19-10
802.1X Mitigation Example
19-11
Prerequisites for Mitigation with 802.1X Network Mapping
19-11
Procedure for Mitigation with 802.1X Network Mapping
19-11
Display Dynamic Device Information
19-15
Virtual Private Network Considerations
19-17
Layer 2 Path and Mitigation Configuration Example
19-17
Prerequisites for Layer 2 Path and Mitigation
19-17
Components Used
19-17
Network Diagram
19-18
Procedures for Layer 2 Path and Mitigation
19-19
Add the Cisco Catalyst 5000 with SNMP as the Access Type.
19-19
Add the Cisco Catalyst 6500 with SNMP as Access Type (Layer 2 only).
19-20
Add the Cisco 7500 Router with TELNET as the Access Type
19-21
Verify the Connectivity Paths for Layer 3 and Layer 2
19-22
Perform Mitigation
19-26