Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 33

Security mars local controller
Table of Contents

Advertisement

Chapter 1
STM Task Flow Overview
Task
Bootstrap the reporting devices, mitigation devices, and supporting devices.
3.
For each device identified in the
ensure that the desired communications with MARS occur. Bootstrapping a device involves configuring the
settings for that device, as determined by its role within the STM system. Perform the following bootstrap tasks
as applicable to a device type and its role:
Enable management of the device by the MARS Appliance for mitigation and access.
Install an agent that collects the correct logs for MARS Appliance.
Turn on the correct logging level and logging services.
Direct the logs to the MARS Appliance or identify the appliance to receive or pull those logs as needed.
Enable discovery of the device settings.
Enable the device to receive notifications from the MARS Appliance.
Each device has a different required configuration to ensure that it assumes the role you have envisioned for it in
the STM system. As you consider the devices, their expected role in your STM system will correlate directly with
the configuration of the tasks listed above. In addition, you identify any restrictions imposed by MARS. For
example, MARS may restrict the supported protocols for discovery of a specific device type.
Result: The correct logging levels are enabled on the reporting devices and mitigation devices. The MARS
Appliance can receive or pull any necessary logs from those devices, and it can retrieve configuration settings
and push ACLS to the supported mitigation devices. Any devices that require notification of detected attacks are
configured to receive such notifications from the MARS Appliance. While the MARS Appliance picks up and
stores the events it receives, it does not inspect them until the reporting devices and mitigation devices are defined
and activated in web interface.
Any events published by a device to MARS prior to adding and activating the device in the web interface can
Tip
be queried using the reporting IP address of the device as a match criterion. This technique can be useful for
verifying that the device is properly bootstrapped.
For more information, see:
Device Inventory Worksheet, page 1-18
Supported Reporting and Mitigation Devices, page 3
Bootstrap Summary Table, page 2-12
The log settings sections of the user guides for your reporting devices and mitigation devices
78-17020-01
Device Inventory
Worksheet, you must prepare, or bootstrap, that device to
User Guide for Cisco Security MARS Local Controller
Checklist for Provisioning Phase
1-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents