xxii
User Guide for Cisco Security MARS Local Controller
78-17020-01
Preface
About This Manual
About This Manual
This manual describes the features and functionality of the Local Controller. The layout of this manual
is as follows:
•
Chapter 1, “STM Task Flow Overview,”
recommends a taskflow for planning and implementing
your security threat mitigation system. It ties back to your corporate security policies and presents
a structure deployment and configuration strategy based on two phases: provisioning and
monitoring.
Part 1: Provisioning Phase
. This part details provisioning your network devices to communicate with
MARS. It involves performing device inventories, bootstrapping and configuring the reporting devices
and mitigation devices to communicate with the MARS Appliance, and performing device-side tuning.
•
Chapter 2, “Reporting and Mitigation Devices Overview,”
discusses concepts important to a
successful deployment of MARS. These concepts include selecting among the devices on your
network, understanding the levels of operation, and performing those tasks that affect many devices,
such as defining data pulling schedules.
•
Chapter 3, “Configuring Router and Switch Devices.”
•
Chapter 4, “Configuring Firewall Devices.”
•
Chapter 5, “Configuring VPN Devices.”
•
Chapter 6, “Configuring Network-based IDS and IPS Devices.”
•
Chapter 7, “Configuring Host-Based IDS and IPS Devices.”
•
Chapter 8, “Configuring Antivirus Devices.”
•
Chapter 9, “Configuring Vulnerability Assessment Devices.”
•
Chapter 10, “Configuring Generic, Solaris, Linux, and Windows Application Hosts.”
•
Chapter 11, “Configuring Database Applications.”
•
Chapter 12, “Configuring Web Server Devices.”
•
Chapter 13, “Configuring Web Proxy Devices.”
•
Chapter 14, “Configuring AAA Devices.”
•
Chapter 15, “Configuring Custom Devices.”
Part II: Monitoring Phase.
This part concepts important to successfully using MARS to monitor your
network. These concepts include defining inspection rules and investigating incidents.
•
Chapter 16, “Policy Table Lookup on Cisco Security Manager”
explains how to integrate with
Cisco Security Manager and use the policy lookup features in MARS.
•
Chapter 17, “Network Summary”
covers the Summary pages which includes the Dashboard, the
Network Status, and the My Reports pages.
•
Chapter 18, “Case Management”
covers using cases to provide accountability and improve
workflow.
•
Chapter 19, “Incident Investigation and Mitigation”
covers incidents and false positives and
provides a starting point for configuring a Layer 2 path and mitigation to work with a MARS.
•
Chapter 20, “Queries and Reports”
covers working with scheduled and on-demand reports and
queries. It also discussing using the real-time event viewer.
•
Chapter 21, “Rules”
covers defining and use inspection rules.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...