Configure The Device Running Cisco Ios 12.2 To Generate Required Data; Enable Syslog Messages; Enable Snmp Ro Strings - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 3
Configuring Router and Switch Devices

Configure the Device Running Cisco IOS 12.2 to Generate Required Data

Cisco routers and switches that are running Cisco IOS Software release 12.2 can be configured to
provide different types of data to MARS:
The following topics describe how to configure these settings:

Enable Syslog Messages

To send syslog messages to the MARS Appliance from a device running Cisco IOS Software Release
12.2, follow these steps:
Step 1
Log in to the Cisco IOS device with enabled password.
Step 2
Enter the commands:

Enable SNMP RO Strings

To enable SNMP RO strings for topology discovery on the Cisco IOS device, you must enable the SNMP
server and define the RO community.
To configure the SNMP RO string settings, follow these steps:
Step 1
Enter configuration mode:
Router> enable
78-17020-01
Syslog messages. The syslog messages provide information about activities on the network,
including accepted and rejected sessions.
SNMP traffic. SNMP RO community strings support the discovery of your network's topology.
NAC-specific data. NAC logs events that are specific to its configuration, including Extensible
Authentication Protocol (EAP) over UDP messages and 802.1x accounting messages.
Access lists or NAT statements. You must enable SSH or Telnet access if the configuration on the
Cisco router or swtich includes access lists or NAT statements.
Spanning tree messages (Switch only). You must have STP (spanning tree protocol) configured
correctly on the switches to enable L2 discovery and mitigation. STP provides MARS with access
to the L2 MIB, which is required to identify L2 re-routes of traffic and to perform L2 mitigation.
MARS also uses the MIB to identify trunks to other switches, which are used to populate VLAN
information used in L2 path calculations. STP, which is enabled by default on Cisco Switches,
should remain enabled, as it is required for L2 mitigation.
Enable Syslog Messages, page 3-3
Enable SNMP RO Strings, page 3-3
Enable NAC-specific Messages, page 3-4
Enable L2 Discovery Messages, page 3-12
Enable SDEE for IOS IPS Software, page 3-6
Router(config)#logging source-interface <interface name>
Router(config)#logging trap <logging level desired>
Router(config)#logging <IP address of MARS Appliance>
User Guide for Cisco Security MARS Local Controller
Cisco Router Devices
3-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents