iii
User Guide for Cisco Security MARS Local Controller
78-17020-01
C O N T E N T S
Preface
xix
Introduction
xix
The MARS Appliance
xix
The MARS Web Interface
xix
About This Manual
xx
Obtaining Documentation
xxi
Cisco.com
xxi
Product Documentation DVD
xxi
Ordering Documentation
xxii
Documentation Feedback
xxii
Cisco Product Security Overview
xxii
Reporting Security Problems in Cisco Products
xxii
Product Alerts and Field Notices
xxiii
Obtaining Technical Assistance
xxiii
Cisco Support Website
xxiii
Submitting a Service Request
xxiv
Definitions of Service Request Severity
xxv
Obtaining Additional Publications and Information
xxv
C H A P T E R
1
STM Task Flow Overview
1-1
Checklist for Provisioning Phase
1-2
Checklist for Monitoring Phase
1-9
Strategies for Monitoring, Notification, Mitigation, Remediation, and Audit
1-16
Appliance-side Tuning Guidelines
1-17
Device Inventory Worksheet
1-18
User Role Worksheet
1-20
C H A P T E R
2
Reporting and Mitigation Devices Overview
2-1
Levels of Operation
2-1
Selecting the Devices to Monitor
2-2
Understanding Access IP, Reporting IP, and Interface Settings
2-8
Access IP
2-9