C H A P T E R
7-1
User Guide for Cisco Security MARS Local Controller
78-17020-01
7
Configuring Host-Based IDS and IPS Devices
Host-based intrusion detection and prevention devices provide MARS with detailed information about
attacks seen at the host level, rather than the network level. They also provide information about the host
operating system and successful prevention of attacks, both of which provide more targeted data for false
positive analysis.
This chapter explains how to bootstrap and add the following host-based IDS and IPS devices to MARS:
•
Entercept Entercept 2.5 and 4.0, page 7-1
•
Cisco Security Agent 4.x Device, page 7-5
Entercept Entercept 2.5 and 4.0
To configure Entercept in MARS, you must perform the following tasks:
1.
Generate CSV file that identifies each of the Entercept hosts by logging into the host running the
Entercept console and copying the data out of the database table.
2.
Configure the Entercept console to send SNMP traps to the MARS Appliance
3.
Identify the events that should be generated as SNMP traps.
4.
Define a host that represents the management console (Entercept console) in MARS web interface.
5.
From that host in the MARS web interface, import the CSV seed file to identify the Entercept agents
running on other hosts.
The following sections provide details on performing each of these tasks:
•
Extracting Entercept Agent Information into a CSV file (for Entercept Version 2.5), page 7-1
•
Define the MARS Appliance as an SNMP Trap Target, page 7-2
•
Specific the Events to Generate SNMP Traps for MARS, page 7-2
Extracting Entercept Agent Information into a CSV file (for Entercept Version
2.5)
Note
Entercept agent information is saved in a database file on the Entercept console.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...