6-18
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
ISS RealSecure 6.5 and 7.0
•
Restart the ISS daemon for the changes to take effect.
For more information, see
Configure ISS RealSecure to Send SNMP Traps to MARS, page 6-18
.
2.
Add the ISS sensor to MARS as a network-based IDS device. For more information, see
Add an ISS
RealSecure Device as a NIDS, page 6-19
.
3.
Click
Activate
to enable proper processing of received events.
Configure ISS RealSecure to Send SNMP Traps to MARS
To configure an ISS RealSecure sensor, follow these steps:
Step 1
Log into the sensor.
Step 2
Locate the
common.policy
files in these directories:
Microsoft Windows
Program Files\ISS\issSensors\server_sensor_1
Program Files\ISS\issSensors\network_sensor_1
Linux
/opt/ISS/issSensors/server_sensor_1
/opt/ISS/issSensors/network_sensor_1
Step 3
Open the
common.policy
files in a text editor.
Step 4
Change the line that reads:
Manager =S
to:
Manager =S <MARS’s IP address>
If MARS Appliance’s IP address is NATed, you may need to use the NATed address. If you use the
MARS Appliance’s IP address as the destination IP address, make sure the SNMP trap can reach MARS
Appliance.
Step 5
Save these edited files and exit the editor.
Step 6
Locate the
current.policy
files in these directories:
Microsoft Windows
Program Files\ISS\issSensors\server_sensor_1
Program Files\ISS\issSensors\network_sensor_1
Linux
/opt/ISS/issSensors/server_sensor_1
/opt/ISS/issSensors/network_sensor_1
Step 7
Open the
current.policy
files in a text editor.
Edit each signature to have SNMP as one of its responses, and set the choice for SNMP trap as default.
For example, in this original signature:
[\template\features\AOLIM_File_Xfer\Response\];
[\template\features\AOLIM_File_Xfer\Response\DISPLAY\];
Choice =S Default;
[\template\features\AOLIM_File_Xfer\Response\LOGDB\];
Choice =S LogWithoutRaw;
Insert the following bolded lines to make it look similar to the following: