1-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 1 STM Task Flow Overview
Checklist for Provisioning Phase
2.
Identify and enable all required traffic flows.
After you identify the devices, you must verify that the network services they use for management, reporting, and
notification are permitted along the required traffic flows. Using the detailed
Device Inventory Worksheet
identified in Step
1.
, ensure that the management, logging, and notification traffic between the MARS Appliance
and each supporting device, reporting device, and mitigation device is allowed by intermediate gateways.
In addition, network services of supporting devices, such as DNS, e-mail, AAA, and NTP servers, must also be
permitted to flow among the MARS Appliance, the supporting devices, and the reporting devices and mitigation
devices on your network.
MARS applies the device time to received events only. For all events pulled from devices such as IDS/IPS devices
or Windows, MARS uses the reported time as long as that reported time falls within 3600 seconds of the time on
the MARS Appliance.
Tip
It is a recommended security practice to have all devices, including MARS Appliances, synchronized to the
same time. Also, since the MARS Appliance is an HTTPS server, it uses certificates which require the time,
date, and time zone to be set properly. Otherwise, sessions and incidents are stamped incorrectly and you may
experience “time out” errors when accessing the web interface.
To limit troubleshooting, you should test each traffic flow from the source network segment to the destination
segment. If possible, you should test all device-to- device flows for each protocol to ensure that best match versus
first match semantics of various gateway ACLs do not hinder required traffic flows. As with any security devices
on your network, enabled traffic flows should be restricted to the required protocols, ports, and source/destination
pairs.
Result
: You have verified that all intermediate gateways permit the log, management, and notification traffic
between the devices and the MARS Appliance.
For more information, see:
•
Event Timestamps and Processing
in
Top Issues for the Cisco Security Monitoring, Analysis, and Response
System
•
Deployment Planning Guidelines, page 2-1
, in
Install and Setup Guide for Cisco Security Monitoring,
Analysis, and Response System
•
Supporting Devices, page 2-1
, in
Install and Setup Guide for Cisco Security Monitoring, Analysis, and
Response System
•
Required Traffic Flows, page 2-2
, in
Install and Setup Guide for Cisco Security Monitoring, Analysis, and
Response System
•
Specify the Time Settings, page 5-10
, in
Install and Setup Guide for Cisco Security Monitoring, Analysis,
and Response System
•
Device Inventory Worksheet, page 1-18
Task