Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 32

Security mars local controller
Table of Contents

Advertisement

Checklist for Provisioning Phase
Task
Identify and enable all required traffic flows.
2.
After you identify the devices, you must verify that the network services they use for management, reporting, and
notification are permitted along the required traffic flows. Using the detailed
identified in Step 1., ensure that the management, logging, and notification traffic between the MARS Appliance
and each supporting device, reporting device, and mitigation device is allowed by intermediate gateways.
In addition, network services of supporting devices, such as DNS, e-mail, AAA, and NTP servers, must also be
permitted to flow among the MARS Appliance, the supporting devices, and the reporting devices and mitigation
devices on your network.
MARS applies the device time to received events only. For all events pulled from devices such as IDS/IPS devices
or Windows, MARS uses the reported time as long as that reported time falls within 3600 seconds of the time on
the MARS Appliance.
It is a recommended security practice to have all devices, including MARS Appliances, synchronized to the
Tip
same time. Also, since the MARS Appliance is an HTTPS server, it uses certificates which require the time,
date, and time zone to be set properly. Otherwise, sessions and incidents are stamped incorrectly and you may
experience "time out" errors when accessing the web interface.
To limit troubleshooting, you should test each traffic flow from the source network segment to the destination
segment. If possible, you should test all device-to- device flows for each protocol to ensure that best match versus
first match semantics of various gateway ACLs do not hinder required traffic flows. As with any security devices
on your network, enabled traffic flows should be restricted to the required protocols, ports, and source/destination
pairs.
Result: You have verified that all intermediate gateways permit the log, management, and notification traffic
between the devices and the MARS Appliance.
For more information, see:
Event Timestamps and Processing
System
Deployment Planning Guidelines, page
Analysis, and Response System
Supporting Devices, page
Response System
Required Traffic Flows, page
Response System
Specify the Time Settings, page
and Response System
Device Inventory Worksheet, page 1-18
User Guide for Cisco Security MARS Local Controller
1-4
in Top Issues for the Cisco Security Monitoring, Analysis, and Response
2-1, in Install and Setup Guide for Cisco Security Monitoring,
2-1, in Install and Setup Guide for Cisco Security Monitoring, Analysis, and
2-2, in Install and Setup Guide for Cisco Security Monitoring, Analysis, and
5-10, in Install and Setup Guide for Cisco Security Monitoring, Analysis,
Chapter 1
STM Task Flow Overview
Device Inventory Worksheet
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents