19-17
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Layer 2 Path and Mitigation Configuration Example
Virtual Private Network Considerations
Currently, MARS cannot display accurate Path/Mitigation information or compute the complete route of
an attack originated by a host with a source IP address on a virtual private network (VPN). MARS can
identify the attacking host if the VPN IP address of the host was supplied by a Cisco 3000 Series VPN
Concentrator configured as a MARS reporting device.
Note
You must be able to recognize from your knowledge of your network that the IP address of the attacking
host is an IP address allocated to a VPN.
To identify a host attacking from a VPN, perform a query of “Cisco VPN User connected/disconnected”
events for the Cisco VPN Concentrator device. The attacking host name or next network element is
disclosed in the raw messages of the events.
Layer 2 Path and Mitigation Configuration Example
This section provides a starting point for configuring MARS to perform Layer 2 (L2) path analysis and
mitigation using a Cisco switch. It contains the following sections:
–
Prerequisites for Layer 2 Path and Mitigation, page 19-17
–
Components Used, page 19-17
–
Network Diagram, page 19-18
–
Procedures for Layer 2 Path and Mitigation, page 19-19
–
Add the Cisco Catalyst 6500 with SNMP as Access Type (Layer 2 only)., page 19-20
–
Add the Cisco 7500 Router with TELNET as the Access Type, page 19-21
–
Verify the Connectivity Paths for Layer 3 and Layer 2, page 19-22
–
Perform Mitigation, page 19-26
Prerequisites for Layer 2 Path and Mitigation
•
You need to have the SNMP community strings and IP addresses for the Layer 2 switches and
routers.
•
You must have STP (Spanning Tree Protocol) configured correctly on the switches.
Components Used
•
a Cisco Catalyst 5000 with SNMP access enabled
•
a Cisco Catalyst 6500 for Layer 2 with SNMP access enabled
•
a Cisco 7500 Router with SNMP or TELNET access enabled
•
a MARS running software Version 2.5.1
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...