16-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 16 Policy Table Lookup on Cisco Security Manager
Overview of Cisco Security Manager Policy Table Lookup
The syslog that generated the MARS incident or event may not have sufficient information for Security
Manager to uniquely identify the device or the access rule. In these ambiguous cases, Security Manager
returns a list of all possible devices to MARS in a pop-up window. When the MARS user manually
selects a reporting device, the policy table is then displayed for that device. Access rules that match the
query criteria are highlighted.
Note
The policy table displayed by MARS is the Security Manager Committed View, not the Deployed View,
meaning the displayed Security Manager policies are saved in the Security Manager database but not yet
deployed on the device. If the deployed and committed views are not identical, the access rule generating
the MARS event may not be visible in the policy table displayed by MARS. For further information on
Cisco Security Manager operation, please access the documentation at the following URL:
http://www.cisco.com/en/US/products/ps6498/tsd_products_support_series_home.html
More About Cisco Security Manager Device Lookup
MARS requests the Policy Table of a Security Manager device by supplying the following criteria to
Security Manager:
•
Device Name—Derived from MARS Device Name
•
IP Address—Derived from MARS Reporting IP
•
Domain Name—If available, derived from the device name in MARS (for example,
c3550-225-125.clab.cisco.com)
•
Device Type—If available from MARS
The Device Lookup query includes the following actions between MARS and Security Manager:
1.
Security Manager matches the MARS Device Name to the Security Manager host names. If only one
matching host name is discovered, the process for Policy Table Lookup is invoked.
2.
If the Security Manager host name is undefined, then Security Manager matches the MARS
Device Name with the Security Manager Display Name (display names are unique, but the host
name may be a substring of many display names.)
3.
If there are multiple matches on host name and no unique display name matches, the domain name
(if available) is used to narrow the choices.
4.
If the domain name is not available, MARS Reporting IP is used to narrow the choices.
5.
If a unique device cannot be identified, MARS displays a list of possible devices in a pop-up window
that shows the IP address, host name, display name, and domain name for all possible device
matches. The user manually selects the device and the process for the policy table lookup is invoked.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...