Iss Site Protector - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 6
Configuring Network-based IDS and IPS Devices
To manually define the networks, select the Define a Network radio button.
a.
b.
c.
d.
To select the networks that are attached to the device, click the Select a Network radio button.
a.
b.
c.
Click Test Connectivity to verify the configuration.
Step 12
To save your changes, click Submit.
Step 13
To enable MARS to start sessionizing events from this module, click Activate.
Step 14

ISS Site Protector

This topic describes how to use Site Protector to configure the ISS NIDS and HIDS; Site Protector is not
Note
a device type that can be monitored or used as an aggregation point for ISS event data from the
perspective of MARS. MARS cannot parse event data from Site Protector, unless you develop a custom
event parser for each event type as described in
MARS supports ISS NIDS and HIDS event retrieval via SNMP. However, when configuring ISS
RealSecure sensors (NIDS) and hosts (HIDS), you must configure each active signature to send an alert
to the MARS Appliance. This task can be very tedious as it must be done for each sensor and after each
signature upgrade, as it resets the redirect configuration. One approach to simplifying this task is to use
the ISS Site Protector management console to define these changes globally and apply them to each
sensor.
ISS Site Protector 2.0 allows you to centrally manage SNMP alert destinations, such as the MARS
Appliance, for group policies. You can then push these group policies to all desired host and network
sensors. For each ISS signature update, you must specify the MARS Appliance as an SNMP alert
destination before you apply the downloaded signatures to sensors using Site Protector.
By default, the group policy response configuration is supported only on Proventia G400 and G2000
Note
models. For all other models, including the G100 mentioned, a firmware upgrade is required. See the
documentation that came with ISS Site Protector for more information.
To perform the major configuration steps required to use Site Protector to forward the SNMP alerts
generated by sensors to MARS Appliance, follow these steps:
Using the Add Sensor Wizard, register the sensor to Site Protector Console.
Step 1
78-17020-01
Enter the network address in the Network IP field.
Enter the corresponding network mask value in the Mask field.
Click Add to move the specified network into the Monitored Networks field.
Repeat as needed.
Select a network from in the Select a Network list.
Click Add to move the selected network into the Monitored Networks field.
Repeat as needed.
Adding User Defined Log Parser Templates, page
User Guide for Cisco Security MARS Local Controller
ISS Site Protector
15-1.
6-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents