6-10
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
Cisco IPS Modules
Verify that MARS Pulls Events from a Cisco IPS Device
Note
If the Test Connectivity operation does not fail when configuring a Cisco IPS device in the MARS web
interface, then communications are enabled. This task allows you to further verify the alerts are
generated and pulled correctly.
It is common to create benign events on the network to verify the data flow. To verify the data flow
between a Cisco IPS device and MARS, perform the following tasks:
1.
On the Cisco IPS device, enable and alert on the signatures 2000 and 2004. The signatures monitor
ICMP messages (pings).
2.
Ping a device on the subnet on which the Cisco IPS device is listening. The events are generated and
pulled by MARS.
3.
Verify that the events appear in the MARS web interface. You can perform a query using the
Cisco IPS device.
4.
Once the dataflow is verified, you can disable the 2000 and 2004 signatures on the Cisco IPS device.
Cisco IPS Modules
MARS can monitor Cisco IPS modules installed in Cisco switches and Cisco ASA appliances. To
prepare these modules, you must perform the following tasks:
•
Define the base module, either the router, switch, or Cisco ASA, as defined in
Cisco Router Devices,
page 3-1
,
Cisco Switch Devices, page 3-9
, and
Cisco Firewall Devices (PIX, ASA, and FWSM),
page 4-1
.
•
Bootstrap the base module to enable SDEE traffic on the Cisco IPS module, to forward events to the
MARS Appliance, and to enable MARS to access the SDEE events stored on the modules. Module
access enables MARS to retrieve trigger packets and IP log information.
•
Add the IPS feature set t the base module previously defined in the web interface.
This section contains the following topics:
•
Enable DTM Support, page 6-10
•
Enable SDEE on the Cisco IOS Device with an IPS Module, page 6-11
•
Add an IPS Module to a Cisco Switch or Cisco ASA, page 6-11
The following topic also supports the configuration of the Cisco IPS modules:
•
Verify that MARS Pulls Events from a Cisco IPS Device, page 6-10
Enable DTM Support
To support DTM, you must configure your IPS module as follows:
•
Purchase or enable the IOS IPS feature set.
•
Enable HTTPS for SDEE.
•
Enable SSH to discover settings, which is the method recommended over Telnet.