Enable Sdee For Ios Ips Software; Add And Configure A Cisco Router In Mars - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Cisco Router Devices
After you configure the switch to act as proxy and it is defined as a AAA client in Cisco Secure ACS,
you must ensure that the authentication messages are sent to the MARS Appliance. For 802.1x
accounting records, you must ensure that the audit records are written to the RADIUS log on the
Cisco Secure ACS server. To configure these settings, refer
Logs, page

Enable SDEE for IOS IPS Software

Before you enable SDEE, you must enable either Telnet or SSH as the access type for configuration
discovery on a Cisco IOS device. You must also enable SDEE on the device that supports the IOS IPS
software feature. SDEE is used to publish events to MARS about signatures that have fired.
To enable SDEE protocol on the Cisco IOS device that supports IOS IPS, follow these steps:
Log in to the Cisco IOS device using the enable password.
Step 1
Enter the following commands to enable MARS to retrieve events from the IOS IPS software:
Step 2
Note
The "no ips notify log" causes the IOS IPS software to stop sending IPS events over syslog.

Add and Configure a Cisco Router in MARS

Cisco routers provide data about the network and its activities in the form of syslog messages and SNMP
RO MIBs. In addition, MARS can discover settings, such as network address translations, attached
networks, and active access rules, that improve the accuracy of false positive identification, attack path
analysis, and L3 network discovery.
To add a Cisco router running Cisco IOS 12.2 or later, follow these steps:
Select Admin > System Setup > Security and Monitor Devices > Add.
Step 1
Select Cisco IOS 12.2 from the Device Type list.
Step 2
User Guide for Cisco Security MARS Local Controller
3-6
14-3.
Router(config)#ip http secure-server
Router(config)#ip ips notify sdee
Router(config)#ip sdee subscriptions 3
Router(config)#ip sdee events 1000
Router(config)#no ip ips notify log
Chapter 3
Configuring Router and Switch Devices
toConfigure Cisco Secure ACS to Generate
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents