9-8
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 9 Configuring Vulnerability Assessment Devices
Qualys QualysGuard Devices
Step 7
(Optional) To verify that the settings are correct and that the MARS Appliance can communicate with
this Qualys device, click
Test Connectivity
.
If you receive error messages during this test, refer to
Troubleshooting QualysGuard Integration, page
9-9
.
Step 8
To add this device to the MARS database, click
Submit
.
Once you activate this device (click Activate in the web interface), you must define the schedule at which
MARS should pull data from it. For more information, see
Schedule the Interval at Which Data is Pulled,
page 9-8
.
Schedule the Interval at Which Data is Pulled
Once you activate one or more Qualys devices (where each device represents a report query run on the
QualysGuard API Server), you must define the schedule at which MARS pulls data from them. The
schedule, or update rule, that you define is the same for all Qualys devices. This update rule is based on
the fixed IP address of 165.193.18.12, which is the Qualys Access IP. When you define an update rule
using this address, all Qualys devices are updated based on that schedule. Even if you have more than
one Qualys device on your network, you cannot stagger when MARS queries those Qualys devices.
However, you can define unique schedules across different Local Controllers.
For more information on the broader use of update rules, see
Scheduling Topology Updates, page 2-39
.
To define the rule by which all Qualys devices will be discovered, follow these steps:
Step 1
Click
Admin
>
Topology/Monitored Device Update Scheduler
.
The Topology/Monitored Device Update Scheduler page displays.
Step 2
Click
Add
.
Step 3
Enter
Qualys Devices
or another meaningful value in the Name field.
This name identifies the rule in the list of rules that appears on the Topology/Monitored Device Update
Scheduler page.
Step 4
Select the
Network IP
radio button, and enter 165.193.18.12. and 255.255.255.255 in the Network IP
and Mask fields respectively.
Step 5
Click
Add
to move the device into the selected field.
Step 6
In the Schedule table, select
Daily
, and select a time value from
Time of Day
list.
We recommend that you pull this data daily, during off-peak hours, however, you can define any interval
required by your organization.
Step 7
Click
Submit
.
The update rule appears in the list on the Topology/Monitored Device Update Scheduler page.
Step 8
Click
Activate
.
Tip
To perform this discovery on demand, select the check box next to the rule you just defined and click
Run Now
.