3-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 3 Configuring Router and Switch Devices
Cisco Router Devices
Configure the Device Running Cisco IOS 12.2 to Generate Required Data
Cisco routers and switches that are running Cisco IOS Software release 12.2 can be configured to
provide different types of data to MARS:
•
Syslog messages.
The syslog messages provide information about activities on the network,
including accepted and rejected sessions.
•
SNMP traffic.
SNMP RO community strings support the discovery of your network’s topology.
•
NAC-specific data.
NAC logs events that are specific to its configuration, including Extensible
Authentication Protocol (EAP) over UDP messages and 802.1x accounting messages.
•
Access lists or NAT statements.
You must enable SSH or Telnet access if the configuration on the
Cisco router or swtich includes access lists or NAT statements.
•
Spanning tree messages
(Switch only). You must have STP (spanning tree protocol) configured
correctly on the switches to enable L2 discovery and mitigation. STP provides MARS with access
to the L2 MIB, which is required to identify L2 re-routes of traffic and to perform L2 mitigation.
MARS also uses the MIB to identify trunks to other switches, which are used to populate VLAN
information used in L2 path calculations. STP, which is enabled by default on Cisco Switches,
should remain enabled, as it is required for L2 mitigation.
The following topics describe how to configure these settings:
•
Enable Syslog Messages, page 3-3
•
Enable SNMP RO Strings, page 3-3
•
Enable NAC-specific Messages, page 3-4
•
Enable L2 Discovery Messages, page 3-12
•
Enable SDEE for IOS IPS Software, page 3-6
Enable Syslog Messages
To send syslog messages to the MARS Appliance from a device running Cisco IOS Software Release
12.2, follow these steps:
Step 1
Log in to the Cisco IOS device with enabled password.
Step 2
Enter the commands:
Router(config)#logging source-interface <interface name>
Router(config)#logging trap <logging level desired>
Router(config)#logging <IP address of MARS Appliance>
Enable SNMP RO Strings
To enable SNMP RO strings for topology discovery on the Cisco IOS device, you must enable the SNMP
server and define the RO community.
To configure the SNMP RO string settings, follow these steps:
Step 1
Enter configuration mode:
Router>
enable
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...