2-35
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Data Enabling Features
Step 2
Under
NetFlow Configuration
, enter the NetFlow
Global NetFlow UDP Port
. This is the default port
for MARS to listen for NetFlow; the default value is 2055.
Note
This value must match the value you entered in the “
ip flow-export destination
” command when
configuring the router (see
Enable Cisco IOS Routers and Switches to Send NetFlow to MARS, page
2-32
. Also, verify you have enabled this traffic to flow between the router or switch and the MARS
Appliance on any intermediate gateways, such as routers and firewalls.
Step 3
Choose whether to
Enable NetFlow Processing
.
•
Yes
tells MARS to process the NetFlow logs.
•
No
disables the processing of NetFlow data into the MARS.
Step 4
Choose whether to
Always Store NetFlow Records
.
•
Yes
tells MARS to store all of the NetFlow events in the database. Selecting this option can slow
down the system by greatly decreasing the number of events per second that MARS is able to
process.
•
No
tells MARS to store only anomalies. The MARS detects anomalies by using two dynamically
generated watermarks comparing the previous data against current data. When the data breaches the
first watermark, MARS starts to save that data. When the data rises above the second watermark,
MARS creates an incident.
Step 5
Under
NetFlow Valid Network Addresses
, you can enter one or more for networks you want to monitor
and use the
<< Add
button to add them.