Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 193

Security mars local controller
Table of Contents

Advertisement

Chapter 6
Configuring Network-based IDS and IPS Devices
In the routes file add a line indicating your MARS appliances' name and its IP address;
e.g., pnmars.protego 1 10.1.1.10 45000 1 5
where pnmars.protego is the MARS's name (with organizations' name) followed by 1 then the
MARS appliances' IP address.
The 45000 is the port number that the IDS will use to send its logs to MARS. Add a 1 follows by a 5 at
the end of this line (these numbers are not used by MARS).
Figure 6-3
In the destinations file add a line indicating your MARS appliances' name (as defined in the routes file)
the client process that the appliance is using to listen for events from the sensor (in this case smid), and
the list of log types you want sent to the appliance as a comma separated list:
e.g.,
where
of log types that the loggerd daemon will publish to the appliance.
78-17020-01
Add MARS Information to Cisco IDS 3.1 Routes File
pnmars.protego smid ERRORS, EVENTS, COMMANDS
is the MARS's name (with organizations' name) followed by smid and the list
pnmars.protego
User Guide for Cisco Security MARS Local Controller
Cisco IDS 3.1 Sensors
6-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents