4-47
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Check Point Devices
Before you can specify the SNMP RO string, you must define an access IP address on host that
represents the primary management station. MARS uses the SNMP RO string to read MIBs related to a
reporting device’s CPU usage, network usage, and device anomaly data and to discover device and
network settings .
Step 9
Under Enter interface information, enter the interface name, IP address, and netmask value of each
interface installed in the child enforcement module or log server.
These interfaces include the ones from which the configuration information will be discovered and
security event logs will be pulled. To learn more about the interface settings, its role, and dependencies,
see
Understanding Access IP, Reporting IP, and Interface Settings, page 2-8
.
Step 10
Click
Submit
to add this module to the primary management station.
Step 11
(Optional) To specify the route information for a firewall child enforcement module, continue with
Define Route Information for Check Point Firewall Modules, page 4-50
.
Step 12
If the child enforcement module does not propagate its logs to the primary management station or if you
are defining a log server that is not managed by this primary management station, you must specify
where its logs are stored. Continue with
Specify Log Info Settings for a Child Enforcement Module or
Log Server, page 4-52
.
Step 13
Repeat
Step 5
through
Step 12
for each child enforcement module that is managed by this primary
management station and each log server that is used by the primary management station or child
enforcement modules.
Step 14
To add this device to the MARS database, click
Submit
.
Result
: The submit operation records the changes in the database tables. However, it does not load the
changes into working memory of the MARS Appliance. The activate operation loads submitted changes
into working memory.
Step 15
Click
Done
to close the Reporting Applications tab and return to the Security and Monitoring Devices
list.
Step 16
Click
Activate
.
Result
: Once the MARS Appliance is activated, it connects to the Check Point log modules and retrieves
the traffic and audit logs. MARS also begins to sessionize events generated by this device and its
modules and evaluate those events using the defined inspection and drop rules. Any events published by
the device to MARS before activation can be queried using the reporting IP address of the device as a
match criterion. For more information on the activate action, see
Activate the Reporting and Mitigation
Devices, page 2-27
.
Add a Check Point Certificate Server
When defining a Check Point module that uses secured communications, you must identify the
certificate sever that authenticates the SICs provided by the client and the server. Typically, a
SmartCenter server or the CMA has its own certificate server, however, your configuration may use a
central server. If that is the case, you must define the certificate server as part of a defining a base or
child enforcement module.
Note
This procedure assumes you have been refer to it, and that you are in the middle of defining a primary
management station or child enforcement module.
To define a certificate server, follow these steps: