2-13
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Bootstrap Summary Table
Table 2-3
Reporting and Mitigation Device Bootstrap Summary
Device Type/Name
Bootstrap Summary
Reference Information
Router/Switch
Cisco Router
1.
Access to IP address/interface by MARS.
2.
FTP, SNMP, Telnet or SSH access by MARS.
3.
Define SNMP RO community string.
4.
Turn on syslog, define log level, and define
MARS as target of syslog messages.
5.
Enable NAC features.
Cisco Router Devices, page 3-1
Cisco Switch (IOS)
Cisco Switch Devices, page 3-9
Cisco Switch (CatOS)
Extreme ExtremeWare
1.
Access to IP address/interface by MARS.
2.
(ExtremeWare only) Turn on syslog, define
log level, and define MARS as target of syslog
messages.
3.
SNMP access by MARS.
4.
Define SNMP RO community string.
Extreme ExtremeWare 6.x, page 3-17
Generic Router
Generic Router Device, page 3-18
Firewall Devices
Cisco PIX
1.
Access to access and reporting IP
address/interface by MARS.
2.
FTP, Telnet, or SSH access by MARS.
3.
Define SNMP RO community string.
Note
SNMP settings should be defined for the
admin context on ASA and FWSM. You
do not need to define these settings for
each security context.
4.
Turn on syslog, define log level, and define
MARS as target of syslog messages.
Bootstrap the Cisco Firewall Device, page 4-2
Cisco Adaptive Security
Appliance (ASA)
Cisco Firewall Services
Module (FWSM)
Cisco IOS Firewall
Feature Set
Juniper Netscreen
NetScreen ScreenOS Devices, page 4-14
Checkpoint Opsec NG
and Firewall-1
1.
Add the MARS Appliance as a host.
2.
Create and install an OPSEC Application
object for the defined host.
3.
Define policies to permit SIC traffic between
the MARS Appliance, the Check Point
management server, and any remote servers.
4.
Define the log settings to push the correct
events to the defined host.
5.
Install the policies.
Bootstrap the Check Point Devices, page 4-25
Nokia Firewall (running
Checkpoint)
VPN Devices
Cisco VPN
Concentrator
Cisco VPN 3000 Concentrator, page 5-1