6-13
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
ISS Site Protector
To manually define the networks, select the Define a Network radio button.
a.
Enter the network address in the Network IP field.
b.
Enter the corresponding network mask value in the Mask field.
c.
Click
Add
to move the specified network into the Monitored Networks field.
d.
Repeat as needed.
To select the networks that are attached to the device, click the Select a Network radio button.
a.
Select a network from in the Select a Network list.
b.
Click
Add
to move the selected network into the Monitored Networks field.
c.
Repeat as needed.
Step 12
Click
Test Connectivity
to verify the configuration.
Step 13
To save your changes, click
Submit
.
Step 14
To enable MARS to start sessionizing events from this module, click
Activate
.
ISS Site Protector
Note
This topic describes how to use Site Protector to configure the ISS NIDS and HIDS; Site Protector is not
a device type that can be monitored or used as an aggregation point for ISS event data from the
perspective of MARS. MARS cannot parse event data from Site Protector, unless you develop a custom
event parser for each event type as described in
Adding User Defined Log Parser Templates, page 15-1
.
MARS supports ISS NIDS and HIDS event retrieval via SNMP. However, when configuring ISS
RealSecure sensors (NIDS) and hosts (HIDS), you must configure each active signature to send an alert
to the MARS Appliance. This task can be very tedious as it must be done for each sensor and after each
signature upgrade, as it resets the redirect configuration. One approach to simplifying this task is to use
the ISS Site Protector management console to define these changes globally and apply them to each
sensor.
ISS Site Protector 2.0 allows you to centrally manage SNMP alert destinations, such as the MARS
Appliance, for group policies. You can then push these group policies to all desired host and network
sensors. For each ISS signature update, you must specify the MARS Appliance as an SNMP alert
destination before you apply the downloaded signatures to sensors using Site Protector.
Note
By default, the group policy response configuration is supported only on Proventia G400 and G2000
models. For all other models, including the G100 mentioned, a firmware upgrade is required. See the
documentation that came with ISS Site Protector for more information.
To perform the major configuration steps required to use Site Protector to forward the SNMP alerts
generated by sensors to MARS Appliance, follow these steps:
Step 1
Using the Add Sensor Wizard, register the sensor to Site Protector Console.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...