2-34
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Data Enabling Features
Step 5
To exit enable mode, enter the following command:
exit
Configuring Cisco CatIOS Switch
Some Cisco Catalyst switches support a different implementation of NetFlow that is performed on the
supervisor. With the cache-based forwarding model, which is implemented in the Catalyst 55xx running
the Route Switch Module (RSM) and NetFlow Feature Card (NFFC), the RSM processes the first flow
and the remaining packets in the flow are forwarded by the Supervisor. This support is also implemented
in the early versions of the 65xx with MSFC. The deterministic forwarding model used in the 65xx with
MSFC2 do not use NetFlow to determine the forwarding path, the flow cache is only used for statistics
as in the current IOS implementations. In all of these configurations, flow exports arrive from both the
RSM/MSFC and the Supervisor engines as distinct streams.
The router-side running IOS is configured as specified in
Enable Cisco IOS Routers and Switches to
Send NetFlow to MARS, page 2-32
. However, to configure the he CatIOS NetFlow Data Export, use the
following commands:
set mls flow full
set mls nde version 5
set mls nde <
MARS_IP_address
> 2055
set mls nde enable
From a user’s perspective, the switch is only running IOS when the 65xx is running in Native mode.
Enable NetFlow Processing in MARS
Once you have enabled NetFlow on your routers or switches and you have directed those devices to
publish NetFlow data to the MARS Appliance, you must configure the appliance to process that data.
This configuration involves determining how to store data, as well as identifying which networks you
want to process for anomalous behavior. Both of these options can affect the rate at which MARS can
process events: storing the full event data rather than summary data burdens the system with writing
large volumes of data rather than processing new incoming events. Also, by not specifying a select set
of networks, MARS studies all networks.
Step 1
Click
Admin > System Setup > NetFlow Config Info
.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...