19-15
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Mitigation
Figure 19-11
Mitigation Confirmation Dialog
Step 8
Click
Yes
to confirm.
Display Dynamic Device Information
To display current, session, and all historical information for an IP address on an 802.1X connection,
follow these steps:
Step 1
Click on the Incident ID to display the session summaries as shown in
Figure 19-8
.
Step 2
Click on the
Source IP/Port
or
Destination IP
link of a session.
When examining an attacking host, the Source IP address is more relevant.
Step 3
The current connection information pop-up window appears to display any static connection
information.
Step 4
Click
Dynamic Info
to display current connection information, as shown in
Figure 19-11
.
Dynamic information can be derived from 802.1X configurations, Cisco Security Agents, or from other
security software suites. The current connection information is the most recent network information
available for the selected IP address.
Step 5
Click
Session
to display the connections related to the specific session, a shown in
Figure 19-13
.