6-19
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
ISS RealSecure 6.5 and 7.0
[\template\features\AOLIM_File_Xfer\Response\];
[\template\features\AOLIM_File_Xfer\Response\DISPLAY\];
Choice =S Default;
[\template\features\AOLIM_File_Xfer\Response\SNMP\];
Choice =S Default;
[\template\features\AOLIM_File_Xfer\Response\LOGDB\];
Choice =S LogWithoutRaw;
Step 8
Save these edited files and exit the editor.
Step 9
Locate the
response.policy
files in these directories:
Microsoft Windows
Program Files\ISS\RealSecure SiteProtector\Console
Linux
/opt/ISS/RealSecure SiteProtector/Console
Step 10
Edit the
response.policy
files to specify the IP of the SNMP manager (MARS Appliance) and the
community string:
SMTP_HOST
=S
;
addr_1
=S
;
[\Response\SNMP\];
[\Response\SNMP\Default\];
Manager
=S
;
Community
=S
public;
to:
Manager =S <MARS’s IP address> ;
Community = S <string> public;
If MARS Appliance’s IP address is NATed, you may need to use the NATed address. If you use the
MARS Appliance’s IP address as the destination IP address, make sure the SNMP trap can reach MARS
Appliance.
Step 11
Save these edited files and exit the editor.
Step 12
Restart the ISS daemon.
•
For sensors installed on Microsoft Windows, restart it in the Services menu.
•
For sensors installed on Linux, run:
/etc/init.d/RealSecure stop
/etc/init.d/RealSecure start
Add an ISS RealSecure Device as a NIDS
Step 1
Click
Admin > System Setup > Security and Monitor Devices >
Add
.
Step 2
From the
Device Type
list, select
Add SW Security apps on a new host
or
Add SW security apps on
existing host
.
Step 3
Enter the
Device Name
.
Step 4
Click
Apply
.
Step 5
Click on
Reporting Applications
tab.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...