6-34
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 6 Configuring Network-based IDS and IPS Devices
Enterasys Dragon 6.x
b.
Facility
- Make sure the
local
n
you select is not in use by the syslog daemon
c.
Level
- Select
Debug
d.
Message
- Make sure its in such format:
%TIME% %DATE% SigName=%NAME% from Sensor=%SENSOR%
ScrIP=%SIP% DstIP=%DIP% SrcPort=%SPORT% DstPort=%DPORT%
Protocol=%PROTO%
Step 5
Click
Save
.
Step 6
In the left menu, click
Alarm
.
Step 7
Set the
Type
to
Real-time
and the
Notification Rule
to
syslog
.
Step 8
Click
Save
.
Step 9
In the left menu, click
Deployment
.
Step 10
In the main screen, click
View Configuration
. Make sure the
local
n
set in both notify syslog and alarm
syslog match.
Step 11
In the main screen, click
Deploy and Reset
to confirm the configuration change.
Host-side Configuration
Configure the syslog on the UNIX host
Step 1
Log into the host as the root user.
Step 2
On the same system running the DPM or EFP, edit the file
/etc/syslog.conf
.
Step 3
Make sure
n
in
local
n
matches the syslog entry you used on the DPM or EFP.
Step 4
Add the line
local
n
.* @<mars ip address>
Replacing
n
with the value used in Step 3 and replacing <
mars ip address
> with the IP address of the
MARS Appliance.
Step 5
Restart the syslog daemon by entering:
/etc/rc.d/rc.syslog restart
MARS-side Configuration
Add Configuration Information for the Enterasys Dragon
Step 1
Click
Admin > System Setup > Security and Monitor Devices >
Add
.
Step 2
From the
Device Type
list, select
Add SW Security apps on a new host
or
Add SW security apps on
existing host
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...