Cisco Incident Control Server - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 8
Configuring Antivirus Devices
In the Device Name field, enter the hostname of the server.
Step 3
In the Reporting IP field, enter the IP address of the interface in the ePolicy Orchestrator server from
Step 4
which SNMP traps will originate.
Under Enter interface information, enter the interface name, IP address, and netmask value of the
Step 5
interface in the ePolicy Orchestrator server from which syslog messages will originate.
This address is the same value as the Reporting IP address.
Click Apply.
Step 6
Click Next to move to the Reporting Applications tab.
Step 7
In the Select Application field, select McAfee ePO 3.5, and then click Add.
Step 8
Click Done to save the changes.
Step 9
Click Submit.
Step 10
To activate the device, click Activate.
Step 11

Cisco Incident Control Server

The Cisco Incident Control Server (Cisco ICS) enables extended protection across Cisco IOS routers,
switches, and IPS devices. In coordination with Trend Micro's incident control solutions, Cisco ICS
prevents the spread of day-zero outbreaks in three ways:
To complete the Cisco ICS communication settings, you must perform two tasks: configure Cisco ICS
to send syslog messages to the MARS Appliance, and add the Cisco ICS management server to the
MARS web interface as a reporting device.
This section contains the following topics:
78-17020-01
First, Cisco ICS issues temporary ACLs to those Cisco mitigation devices that can block such
traffic, typically using a protocol and port pair block. This temporary block is referred to as an
Outbreak Prevention ACL (OPACL).
Second, as soon as a signature is available, Cisco ICS updates all Cisco IPS and IDS devices running
on your network with the signature required to detect and prevent the specific threat. This signature
is referred to as an Outbreak Prevention Signature (OPSig).
Third, Cisco ICS can manage supporting products (sold seperately), such as Tend Micros's Damage
Cleanup Services (DCS), which cleans infected hosts by removing trojans and other malware.
Configure Cisco ICS to Send Syslogs to MARS, page 8-14
User Guide for Cisco Security MARS Local Controller
Cisco Incident Control Server
8-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents