8-13
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 8 Configuring Antivirus Devices
Cisco Incident Control Server
Step 3
In the Device Name field, enter the hostname of the server.
Step 4
In the Reporting IP field, enter the IP address of the interface in the ePolicy Orchestrator server from
which SNMP traps will originate.
Step 5
Under Enter interface information, enter the interface name, IP address, and netmask value of the
interface in the ePolicy Orchestrator server from which syslog messages will originate.
This address is the same value as the Reporting IP address.
Step 6
Click
Apply
.
Step 7
Click
Next
to move to the Reporting Applications tab.
Step 8
In the Select Application field, select
McAfee ePO 3.5
, and then click
Add
.
Step 9
Click
Done
to save the changes.
Step 10
Click
Submit
.
Step 11
To activate the device, click
Activate
.
Cisco Incident Control Server
The Cisco Incident Control Server (Cisco ICS) enables extended protection across Cisco IOS routers,
switches, and IPS devices. In coordination with Trend Micro’s incident control solutions, Cisco ICS
prevents the spread of day-zero outbreaks in three ways:
•
First, Cisco ICS issues temporary ACLs to those Cisco mitigation devices that can block such
traffic, typically using a protocol and port pair block. This temporary block is referred to as an
Outbreak Prevention ACL (OPACL).
•
Second, as soon as a signature is available, Cisco ICS updates all Cisco IPS and IDS devices running
on your network with the signature required to detect and prevent the specific threat. This signature
is referred to as an Outbreak Prevention Signature (OPSig).
•
Third, Cisco ICS can manage supporting products (sold seperately), such as Tend Micros’s Damage
Cleanup Services (DCS), which cleans infected hosts by removing trojans and other malware.
To complete the Cisco ICS communication settings, you must perform two tasks: configure Cisco ICS
to send syslog messages to the MARS Appliance, and add the Cisco ICS management server to the
MARS web interface as a reporting device.
This section contains the following topics:
•
Configure Cisco ICS to Send Syslogs to MARS, page 8-14