4-12
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Cisco Firewall Devices (PIX, ASA, and FWSM)
Step 2
In the Device Type list, do one of the following:
•
For Cisco ASA, select
Cisco ASA 7.0
.
•
For PIX 7.0, select
Cisco PIX 7.0
.
•
For FWSM, select
Cisco FWSM
x
.
y
, where
x.y
is the version number of the software running on
the module.
Step 3
Enter the name of the firewall device in the Device Name
field.
MARS maps this name to the reporting IP address. This name is used in topology maps, queries, and in
the Security and Monitoring Device list. For devices that support the discovery operation, such as routers
and firewalls, MARS renames this field’s value to match the name discovered in the device
configuration, which typically uses the
hostname.domain
format. For devices that cannot be discovered,
such as Windows and Linux hosts and host applications, MARS uses the provided value.
Step 4
Enter the name of the security context in the Context Name field.
This name must exactly match the context name defined on the device.
Step 5
Enter the IP address of the security context from which syslog messages or SNMP notifications, or both
are published in the Reporting IP field.
To learn more about the reporting IP address, its role, and dependencies, see
Understanding Access IP,
Reporting IP, and Interface Settings, page 2-8
.
Step 6
(Optional) To enable MARS to retrieve MIB objects for this security context, enter the device’s
read-only community string in the SNMP RO Community field.
Before you can specify the SNMP RO string, you must define an access IP address. MARS uses the
SNMP RO string to read MIBs related to a security context’s CPU usage, network usage, and device
anomaly data and to discover device and network settings .
Step 7
To discover the settings of the defined context click
Discover
.
This discovery collects all of the route, NAT, and ACL-related information. In addition, the name of the
device may change to the
hostname.domain
format if it was not already entered as such.
Step 8
To save your changes, click
Submit
.
Add Discovered Contexts
When you select Discover on a Cisco ASA, PIX 7.0 or FWSM, MARS discovers the contexts that are
defined for that firewall device. However, you must still manually add discovered contents.