2-26
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Adding Reporting and Mitigation Devices
For more information on these settings, see:
•
Configuring Layer 3 Topology Discovery, page 2-37
•
Scheduling Topology Updates, page 2-39
Note
Once the discovery process is complete, you must click
Activate
for MARS to correctly process events
received from that device. For more information, see
Activate the Reporting and Mitigation Devices,
page 2-27
.
Verify Connectivity with the Reporting and Mitigation Devices
After loading the seed file or manually adding devices, you can verify that the devices were loaded by
clicking
Admin
>
System Setup > Security and Monitor Devices
. You should see the devices that you
have added populating this page.
You can test the devices by checking the box next to the name of the device and clicking
Edit
. On the
device’s page, click
Discover
or
Test Connectivity
. The UI displays a “holding pattern” screen while
it connects to the device. When complete, it shows you the device’s discovery screen.
Note
Some devices cannot be checked for connectivity nor can be discovered. The next section,
Discover and
Testing Connectivity Options, page 2-26
, contains a list of devices that can be checked or discovered.
Discover and Testing Connectivity Options
When you add a device, you should check its connectivity or perform the discovery. Checking a device’s
connectivity or discovery analyzes the device’s configuration, checks that MARS can process its events,
and that MARS can understand its NAT information.
You can test these devices for connectivity or perform discovery:
•
Cisco IOS
•
Cisco PIX
•
Cisco ASA
•
Cisco Switch CatOS
•
Cisco Switch IOS
•
Cisco IDS
•
Cisco IDSM
•
Cisco FWSM
•
Cisco Security Manager server
•
Cisco VPN Concentrator 4.x
•
Check Point
•
Extreme ExtremeWare 6.x
•
NetScreen