1-5
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 1 STM Task Flow Overview
Checklist for Provisioning Phase
3.
Bootstrap the reporting devices, mitigation devices, and supporting devices.
For each device identified in the
Device Inventory Worksheet
, you must prepare, or bootstrap, that device to
ensure that the desired communications with MARS occur. Bootstrapping a device involves configuring the
settings for that device, as determined by its role within the STM system. Perform the following bootstrap tasks
as applicable to a device type and its role:
•
Enable management of the device by the MARS Appliance for mitigation and access.
•
Install an agent that collects the correct logs for MARS Appliance.
•
Turn on the correct logging level and logging services.
•
Direct the logs to the MARS Appliance or identify the appliance to receive or pull those logs as needed.
•
Enable discovery of the device settings.
•
Enable the device to receive notifications from the MARS Appliance.
Each device has a different required configuration to ensure that it assumes the role you have envisioned for it in
the STM system. As you consider the devices, their expected role in your STM system will correlate directly with
the configuration of the tasks listed above. In addition, you identify any restrictions imposed by MARS. For
example, MARS may restrict the supported protocols for discovery of a specific device type.
Result
: The correct logging levels are enabled on the reporting devices and mitigation devices. The MARS
Appliance can receive or pull any necessary logs from those devices, and it can retrieve configuration settings
and push ACLS to the supported mitigation devices. Any devices that require notification of detected attacks are
configured to receive such notifications from the MARS Appliance. While the MARS Appliance picks up and
stores the events it receives, it does not inspect them until the reporting devices and mitigation devices are defined
and activated in web interface.
Tip
Any events published by a device to MARS prior to adding and activating the device in the web interface can
be queried using the reporting IP address of the device as a match criterion. This technique can be useful for
verifying that the device is properly bootstrapped.
For more information, see:
•
Device Inventory Worksheet, page 1-18
•
Supported Reporting and Mitigation Devices, page 3
•
Bootstrap Summary Table, page 2-12
•
The log settings sections of the user guides for your reporting devices and mitigation devices
Task