16-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 16 Policy Table Lookup on Cisco Security Manager
Checklist for Security Manager-to-MARS Integration
Task
1.
Inventory overlapping reporting devices and mitigation devices.
MARS supports round-trip policy audit analysis for reporting and mitigation devices that are both managed by
Security Manager and monitored by a MARS Appliance. In other words, MARS can query the policy rules that
generated an audit event log only when the policies are defined using Security Manager. As such, the first step
in integrating MARS and Security Manager involves identifying those devices for which Security Manager is
used to define policy rules. You must also ensure that devices are running a software versions supported by both
MARS and Security Manager.
This list focuses on those devices that Security Manager manages and should include all of the following devices:
•
Cisco ASA appliances, PIX appliances, and FWSM modules
•
Cisco Catalyst 6500 Series Switches
•
Cisco Routers running supported versions of Cisco IOS software
Note
MARS supports PIX 7.0 and ASA 7.0.1 releases; however, it does not support FWSM 3.1. FWSM support is
restricted to FWSM 1.1, 2.2, and 2.3. For current device support information, see
Supported Devices and
Software Versions for Cisco Security MARS.
Note
FWSM support is supported only in Cisco Security Manager Enterprise Edition (Professional-50) and higher,
The Professional version includes support for the management of Cisco Catalyst® 6500 Series switches and
associated services modules; the Standard versions do not include this support.
Result
: The list of devices for which Security Manager manages the security and audit log policies is defined.
The details of each device include device name, reporting IP address, management IP address, management
protocol, administrative account information, and the logging features, levels, and protocols to enable.
For more information, see:
•
Supported Devices and Software Versions for Cisco Security Manager 3.0
•
Supported Devices and Software Versions for Cisco Security MARS
•
Selecting the Devices to Monitor, page 2-2
•
Levels of Operation, page 2-1
•
Deployment Planning Guidelines, page 2-1
in
Install and Setup Guide for Cisco Security Monitoring,
Analysis, and Response System
•
Device Inventory Worksheet, page 1-18