Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 329

Security mars local controller
Table of Contents

Advertisement

Chapter 16
Policy Table Lookup on Cisco Security Manager
Task
Inventory overlapping reporting devices and mitigation devices.
1.
MARS supports round-trip policy audit analysis for reporting and mitigation devices that are both managed by
Security Manager and monitored by a MARS Appliance. In other words, MARS can query the policy rules that
generated an audit event log only when the policies are defined using Security Manager. As such, the first step
in integrating MARS and Security Manager involves identifying those devices for which Security Manager is
used to define policy rules. You must also ensure that devices are running a software versions supported by both
MARS and Security Manager.
This list focuses on those devices that Security Manager manages and should include all of the following devices:
Cisco ASA appliances, PIX appliances, and FWSM modules
Cisco Catalyst 6500 Series Switches
Cisco Routers running supported versions of Cisco IOS software
MARS supports PIX 7.0 and ASA 7.0.1 releases; however, it does not support FWSM 3.1. FWSM support is
Note
restricted to FWSM 1.1, 2.2, and 2.3. For current device support information, see
Software Versions for Cisco Security MARS.
FWSM support is supported only in Cisco Security Manager Enterprise Edition (Professional-50) and higher,
Note
The Professional version includes support for the management of Cisco Catalyst® 6500 Series switches and
associated services modules; the Standard versions do not include this support.
Result: The list of devices for which Security Manager manages the security and audit log policies is defined.
The details of each device include device name, reporting IP address, management IP address, management
protocol, administrative account information, and the logging features, levels, and protocols to enable.
For more information, see:
Supported Devices and Software Versions for Cisco Security Manager 3.0
Supported Devices and Software Versions for Cisco Security MARS
Selecting the Devices to Monitor, page 2-2
Levels of Operation, page 2-1
Deployment Planning Guidelines, page 2-1
Analysis, and Response System
Device Inventory Worksheet, page 1-18
78-17020-01
Checklist for Security Manager-to-MARS Integration
in Install and Setup Guide for Cisco Security Monitoring,
User Guide for Cisco Security MARS Local Controller
Supported Devices and
16-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents