2-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Selecting the Devices to Monitor
Consider distinct goals:
•
Attack detection
•
Attack detection and mitigation
•
Regulatory compliance
•
Full NAC awareness
•
Identify the devices/feature pairs that overlap on the same network segment, where a choice between
device can reduce duplicity or prioritize device performance
Last, you must consider an event tuning method for your monitoring strategy. How you tune your MARS
affects your overall operational costs proportionally to the number of device of a give type that are
monitored. Essentially, if you have the bandwidth available, we recommend that you tune the events at
the MARS Appliance, which reduces your operational costs by tuning at a single point in the network.
However, if bandwidth is a precious commodity, you may chose to tune the event propagation at the
reporting device level, preventing the events from going onto the network.
Table 2-2
identifies the device types, describes what information they can provide, and recommends how
to configure these devices within your network.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...