Virtual Private Network Considerations; Layer 2 Path And Mitigation Configuration Example; Prerequisites For Layer 2 Path And Mitigation; Components Used - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 19
Incident Investigation and Mitigation

Virtual Private Network Considerations

Currently, MARS cannot display accurate Path/Mitigation information or compute the complete route of
an attack originated by a host with a source IP address on a virtual private network (VPN). MARS can
identify the attacking host if the VPN IP address of the host was supplied by a Cisco 3000 Series VPN
Concentrator configured as a MARS reporting device.
You must be able to recognize from your knowledge of your network that the IP address of the attacking
Note
host is an IP address allocated to a VPN.
To identify a host attacking from a VPN, perform a query of "Cisco VPN User connected/disconnected"
events for the Cisco VPN Concentrator device. The attacking host name or next network element is
disclosed in the raw messages of the events.

Layer 2 Path and Mitigation Configuration Example

This section provides a starting point for configuring MARS to perform Layer 2 (L2) path analysis and
mitigation using a Cisco switch. It contains the following sections:

Prerequisites for Layer 2 Path and Mitigation

Components Used

78-17020-01
Prerequisites for Layer 2 Path and Mitigation, page 19-17
Components Used, page 19-17
Network Diagram, page 19-18
Procedures for Layer 2 Path and Mitigation, page 19-19
Add the Cisco Catalyst 6500 with SNMP as Access Type (Layer 2 only)., page 19-20
Add the Cisco 7500 Router with TELNET as the Access Type, page 19-21
Verify the Connectivity Paths for Layer 3 and Layer 2, page 19-22
Perform Mitigation, page 19-26
You need to have the SNMP community strings and IP addresses for the Layer 2 switches and
routers.
You must have STP (Spanning Tree Protocol) configured correctly on the switches.
a Cisco Catalyst 5000 with SNMP access enabled
a Cisco Catalyst 6500 for Layer 2 with SNMP access enabled
a Cisco 7500 Router with SNMP or TELNET access enabled
a MARS running software Version 2.5.1
Layer 2 Path and Mitigation Configuration Example
User Guide for Cisco Security MARS Local Controller
19-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents