14-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 14 Configuring AAA Devices
Install and Configure the PN Log Agent
Configure Command Authorization for Cisco Routers and Switches
You can use the feature of Cisco Secure ACS to authorize the command sets that MARS is
allowed to execute on a reporting device. The use of this feature is not required by MARS. However, if
you are using this feature on your routers and switches, you must ensure that MARS is allowed to execute
specific commands. Required commands are grouped under two operations: configuration retrieval and
mitigation.
The following commands support configuration retrieval:
•
all
show
commands
•
changeto system
•
changeto context
<
context_name
>
•
enable
•
page
•
no page
•
terminal length 0
•
terminal pager lines 0
•
write terminal
The following commands support mitigation:
•
conf terminal
•
interface
<
interface_name
>
•
shutdown
•
set port disable
<
port_name
>
For more information on configuring command authorization sets in Cisco Secure ACS, see the
following URL:
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00
802335ec.html#wp697557
Install and Configure the PN Log Agent
MARS includes the PN Log Agent to monitor Cisco Secure ACS active log files (failed attempts, passed
authentications, and RADIUS accounting). This agent pushes these log files via syslog to MARS. You
can download the PN Log Agent from the software download center at the following URL:
http://www.cisco.com/cgi-bin/tablebuild.pl/cs-mars-misc
Note
If you are upgrading to a new version of the PN Log Agent, see
Upgrade PN Log Agent to a Newer
Version, page 14-10
.
As part of its operation, the PNLog Agent service writes error and informational message to the
Application Log, which can be viewed using the Event Viewer. To learn more about these messages, see
Application Log Messages for the PN Log Agent, page 14-10
.
To install and configure the PNLog Agent, follow these steps: