Verify That Mars Pulls Events From A Cisco Ips Device; Cisco Ips Modules; Enable Dtm Support - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Cisco IPS Modules

Verify that MARS Pulls Events from a Cisco IPS Device

If the Test Connectivity operation does not fail when configuring a Cisco IPS device in the MARS web
Note
interface, then communications are enabled. This task allows you to further verify the alerts are
generated and pulled correctly.
It is common to create benign events on the network to verify the data flow. To verify the data flow
between a Cisco IPS device and MARS, perform the following tasks:
1.
2.
3.
4.
Cisco IPS Modules
MARS can monitor Cisco IPS modules installed in Cisco switches and Cisco ASA appliances. To
prepare these modules, you must perform the following tasks:
This section contains the following topics:
The following topic also supports the configuration of the Cisco IPS modules:

Enable DTM Support

To support DTM, you must configure your IPS module as follows:
User Guide for Cisco Security MARS Local Controller
6-10
On the Cisco IPS device, enable and alert on the signatures 2000 and 2004. The signatures monitor
ICMP messages (pings).
Ping a device on the subnet on which the Cisco IPS device is listening. The events are generated and
pulled by MARS.
Verify that the events appear in the MARS web interface. You can perform a query using the
Cisco IPS device.
Once the dataflow is verified, you can disable the 2000 and 2004 signatures on the Cisco IPS device.
Define the base module, either the router, switch, or Cisco ASA, as defined in
page
3-1,
Cisco Switch Devices, page
page
4-1.
Bootstrap the base module to enable SDEE traffic on the Cisco IPS module, to forward events to the
MARS Appliance, and to enable MARS to access the SDEE events stored on the modules. Module
access enables MARS to retrieve trigger packets and IP log information.
Add the IPS feature set t the base module previously defined in the web interface.
Enable DTM Support, page 6-10
Enable SDEE on the Cisco IOS Device with an IPS Module, page 6-11
Add an IPS Module to a Cisco Switch or Cisco ASA, page 6-11
Verify that MARS Pulls Events from a Cisco IPS Device, page 6-10
Purchase or enable the IOS IPS feature set.
Enable HTTPS for SDEE.
Enable SSH to discover settings, which is the method recommended over Telnet.
Chapter 6
Configuring Network-based IDS and IPS Devices
3-9, and
Cisco Firewall Devices (PIX, ASA, and FWSM),
Cisco Router Devices,
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents