Contents
vi
User Guide for Cisco Security MARS Local Controller
78-17020-01
Enable FTP-based Administrative Access
3-10
Configure the Device Running CatOS to Generate Required Data
3-11
Enable SNMP RO Strings on CatOS
3-11
Enable Syslog Messages on CatOS
3-11
Enable L2 Discovery Messages
3-12
Add and Configure a Cisco Switch in MARS
3-13
Adding Modules to a Cisco Switch
3-14
Add Available Modules
3-14
Add Cisco IOS 12.2 Modules Manually
3-15
Extreme ExtremeWare 6.x
3-17
Configure ExtremeWare to Generate the Required Data
3-17
Add and Configure an ExtremeWare Switch in MARS
3-18
Generic Router Device
3-18
Add and Configure a Generic Router in MARS
3-19
C H A P T E R
4
Configuring Firewall Devices
4-1
Cisco Firewall Devices (PIX, ASA, and FWSM)
4-1
Bootstrap the Cisco Firewall Device
4-2
Enable Telnet Access on a Cisco Firewall Device
4-4
Enable SSH Access on a Cisco Firewall Device
4-4
Send Syslog Files From Cisco Firewall Device to MARS
4-4
Device-Side Tuning for Cisco Firewall Device Syslogs
4-6
Logging Message Command
4-6
List of Cisco Firewall Message Events Processed by MARS
4-7
Add and Configure a Cisco Firewall Device in MARS
4-8
Add Security Contexts Manually
4-11
Add Discovered Contexts
4-12
Edit Discovered Security Contexts
4-13
NetScreen ScreenOS Devices
4-14
Bootstrap the NetScreen Device
4-15
Add the NetScreen Device to MARS
4-20
Check Point Devices
4-22
Determine Devices to Monitor and Restrictions
4-24
Bootstrap the Check Point Devices
4-25
Add the MARS Appliance as a Host in Check Point
4-26
Define an OPSEC Application that Represents MARS
4-27
Obtain the Server Entity SIC Name
4-30
Select the Access Type for LEA and CPMI Traffic
4-32
Create and Install Policies
4-34