C H A P T E R
5-1
User Guide for Cisco Security MARS Local Controller
78-17020-01
5
Configuring VPN Devices
VPN devices provide MARS with information about remote hosts, login in requests and denials, and
access times. With this data, MARS can provide end-to-end attack path analysis and identify the VPN
device through which attacks are launched.
This chapter explains how to bootstrap and add the following VPN device to MARS:
•
Cisco VPN 3000 Concentrator, page 5-1
Cisco VPN 3000 Concentrator
MARS can receive and process events from the Cisco VPN 3000 Concentrator, versions 4.0.1 and 4.7.
To enable communications, you must perform two tasks:
•
Bootstrap the VPN 3000 Concentrator, page 5-1
•
Add the VPN 3000 Concentrator to MARS, page 5-2
Bootstrap the VPN 3000 Concentrator
To configure a Cisco VPN 3000 Concentrator to generate and publish events to the MARS Appliance,
you must verify that the correct events are generated in the correct format, and you must direct the Cisco
VPN 3000 Concentrator to publish syslog events to the MARS Appliance.
To configure Cisco VPN 3000 Concentrator to send syslog events to MARS, follow these steps:
Step 1
Open your browser and log in to the Cisco VPN 3000 Concentrator Series Manager.
Step 2
From the tree on the left, select
Configuration >
System >
Events >
General
.