7-2
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 7 Configuring Host-Based IDS and IPS Devices
Entercept Entercept 2.5 and 4.0
When you configure the MARS box to add Entercept agents, you can extract them from the database file
on the Entercept console, instead of typing the mapping for each agent.
Create a CSV file for Entercept Agents in Version 2.5
Step 1
Go to the directory
Program Files\Cisco IDS\Console\Database
and copy the file
CoreShield.mdb
to another directory, e.g.:
C:\temp
.
Step 2
Open the copied
CoreShield.mdb
with Microsoft Access, and go to the “Agents” table.
Step 3
Export the table to a file named:
Agents.txt
and choose the exported file format to be CSV.
Step 4
Copy
Agents.txt
to a specific directory that is ready for the MARS box to load.
A sample
agents.txt
file could be:
1,3,"entercept1",6,1,1,1,438,1,"127.0.0.1",0,,1051055867,2086
where the fields are: AgentID, AgentTypeID, ComputerName, ComputerType,
NewFlag, StatusID, OperatingModeID, VersionID, VersionModeID, IP,
License, Note, NoConnection, and UpTime.
Define the MARS Appliance as an SNMP Trap Target
Step 1
Log in to the Entercept Console.
Step 2
Click
Configuration
.
Step 3
Click the
Address Book
tab.
Step 4
In the All Contacts tree, click
SNMP Trap
.
Step 5
Click the Plus (+) button.
Step 6
In the New SNMP Trap page:
a.
Enter an
Alias
for the MARS Appliance.
b.
Set
Privilege
Level to Global.
c.
Set
Status
to Enabled.
d.
Enter the MARS Appliance’s name if the DNS server can resolve the name. Otherwise, use its IP
address.
e.
Enter a community string name in the
Community
field.
f.
Enter a
Port
number.
g.
Select a
Protocol
.
Specific the Events to Generate SNMP Traps for MARS
Step 1
Click the
Notifications
tab.
Step 2
Click the Plus (+) button.