9-5
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 9 Configuring Vulnerability Assessment Devices
Qualys QualysGuard Devices
Step 2
Select
Add SW Security apps on a new host
or
Add SW security apps on existing host
from the
Device Type list.
Step 3
Enter the device name and IP addresses if adding a new host.
Step 4
Click
Apply
.
Step 5
Click the
Reporting Applications
tab.
Step 6
From the Select Application list, select
eEye REM 1.0
.
Step 7
Click
Add
.
Step 8
Enter the following information:
•
Database Name—
The name for this database.
•
Access Port—
The default access port is 1433.
•
Login—
The login information for the database.
•
Password—
The password information for the database.
Step 9
Click
Submit
.
Step 10
Click
Apply
.
Once you activate this device (click Activate in the web interface), you must define the schedule at which
MARS should pull data from it. For more information, see
Scheduling Topology Updates, page 2-39
.
Qualys QualysGuard Devices
In MARS, a QualysGuard device represents a specific report query to the QualysGuard API Server,
which is the central API server hosted by Qualys. The only one that you configure to work with MARS
is the QualysGuard API Server. You want to ensure that the QualysGuard API Server can provide reports
about the devices on the network segments that you are monitoring with the MARS Appliance, as each
MARS Appliance is responsible for identifying false positives for the network segments it monitors.
If you have a subscription to the QualysGuard service, MARS can pull VA data from the QualysGuard
database using the QualysGuard XML API, version 3.3. To configure MARS to pull this data, you must
perform three tasks:
•
Configure QualysGuard to collect the required data, ensuring that the data is current.
•
Add the QualysGuard device that represents a report query to MARS using the web interface.