9-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 9 Configuring Vulnerability Assessment Devices
Qualys QualysGuard Devices
•
Schedule the interval at which the QualysGuard device data is pulled by MARS.
Note
If a proxy server resides between the QualysGuard server and the MARS Appliance, the settings defined
on the Admin > System Parameters > Proxy Settings page are used. For more information, see
Specify
the Proxy Settings for the Global Controller or Local Controller, page 6-18
of the
“
Install and Setup
Guide for Cisco Security Monitoring, Analysis, and Response System, Release 4.2.x.”
This section contains the following topics:
•
Configure QualysGuard to Scan the Network, page 9-6
•
Add and Configure a QualysGuard Device in MARS, page 9-6
•
Schedule the Interval at Which Data is Pulled, page 9-8
•
Troubleshooting QualysGuard Integration, page 9-9
Configure QualysGuard to Scan the Network
MARS uses the QualysGuard XML API and password-based authentication over SSL (TCP port 443) to
retrieve scan reports from the QualysGuard API Server. As such, you do not need to configure the
QualysGuard server to accept connections from MARS. The only required configuration is that you have
an active account and Qualys subscription that is configured correctly to scan your network.
By default, MARS assumes that you want to retrieve the most recent scan report saved on the
QualysGuard server. Depending on the number of IP addresses analyzed, the QualysGuard scan takes
from a few seconds to several minutes. You need to estimate this time so that you can schedule automated
scans of your network with a frequency that ensures a recent saved scan report is available. Using the
QualysGuard administrative interface, you can determine how long a scan takes and set the schedule
accordingly.
Add and Configure a QualysGuard Device in MARS
Adding an internal QualysGuard device as a reporting device entails identifying the QualysGuard API
Server, which is the central API server hosted by Qualys, from which the reports are pulled and providing
credentials that MARS can use to log in to the device to pull the reports. You can specify whether you
want to pull saved scan reports that are run on a schedule or whether you want to initiate and retrieve an
on-demand scan report. Each reporting device identifies a unique query to the QualysGuard API Server.
To add a QualysGuard device, follow these steps:
Step 1
Select
Admin >
Security and Monitor Devices >
Add
.
Step 2
Select
QualysGuard 3.x
from the Device Type
list.