6-5
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
Cisco IDS 4.0 and IPS 5.x Sensors
Figure 6-5
Configure Cisco IDS 3.1
Step 8
For attack path calculation and mitigation, add networks into the Monitored Networks field.
a.
Click the
Select a Network
or
Define a Network
radio button.
•
In the Select a Network list, click a network.
•
In the Define a Network field, enter its network IP and network mask information.
b.
Click
Add
to move the selected networks into the Monitored Networks field.
Step 9
(Optional) To discover the device settings, click
Discover
.
Step 10
Click
Submit
.
Cisco IDS 4.0 and IPS 5.x Sensors
Adding a Cisco IDS or IPS network sensor to MARS involves two parts:
1.
Bootstrap the Sensor, page 6-5
2.
Add and Configure a Cisco IDS or IPS Device in MARS, page 6-6
3.
Verify that MARS Pulls Events from a Cisco IPS Device, page 6-10
The following topic supports Cisco IDS and IPS devices:
•
View Detailed Event Data for Cisco IPS Devices, page 6-9
Note
If you’ve imported your sensor definitions using the seed file format, as specified in
Load Devices From
the Seed File, page 2-24
, you must define the networks monitored by the sensor.
Bootstrap the Sensor
Preparing a sensor to be monitored by MARS involves two steps:
•
Enable the Access Protocol on the Sensor, page 6-6
•
Enable the Correct Signatures and Actions, page 6-6