19-18
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Layer 2 Path and Mitigation Configuration Example
Network Diagram
This section uses the network setup shown in the
Figure 19-14
.
Figure 19-14
Network Setup
Mitigation uses the Layer 2 path data obtained via SNMP or Telnet protocol to download a mitigation
command from the MARS to the device. The Layer 2 path is based on MAC addresses, the Layer 2
forwarding table, and the Layer 3 path. MAC addresses and the Layer 2 forwarding table are obtained
using SNMP.
To make the Layer 2 path and mitigation work correctly:
•
The associated routers must be discovered via SNMP or a combination of SNMP and Telnet,
including the MSFC module in the Catalyst switch.
•
The SNMP community string is necessary for L2 switches to be discovered
Note
L2 devices must be added manually; there is no automatic discovery for these devices.
Make sure all the
L2 devices (switches) have the SNMP RO community strings specified in the web interface, even if the
access type is not SNMP. The SNMP RO community string is always required on Layer 2 devices for L2
mitigation.
•
If the switches are interconnected, make sure STP (Spanning Tree Protocol) is enabled and
configured on them.
143417
Security
appliance
Cisco CatOS 5000
switch
Cisco CatOS 5000
switch
Infected
host
Cisco PIX Firewall
(firewall)
Cisco CatOS 6500
switch (CatSw)
Cisco 7500 Router
(MainRouter)
Internet
Cisco CatOS 5000
switch (KittenSw)
!
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...