Chapter 19
Incident Investigation and Mitigation
Virtual Private Network Considerations
Currently, MARS cannot display accurate Path/Mitigation information or compute the complete route of
an attack originated by a host with a source IP address on a virtual private network (VPN). MARS can
identify the attacking host if the VPN IP address of the host was supplied by a Cisco 3000 Series VPN
Concentrator configured as a MARS reporting device.
You must be able to recognize from your knowledge of your network that the IP address of the attacking
Note
host is an IP address allocated to a VPN.
To identify a host attacking from a VPN, perform a query of "Cisco VPN User connected/disconnected"
events for the Cisco VPN Concentrator device. The attacking host name or next network element is
disclosed in the raw messages of the events.
Layer 2 Path and Mitigation Configuration Example
This section provides a starting point for configuring MARS to perform Layer 2 (L2) path analysis and
mitigation using a Cisco switch. It contains the following sections:
Prerequisites for Layer 2 Path and Mitigation
•
•
Components Used
•
•
•
•
78-17020-01
Prerequisites for Layer 2 Path and Mitigation, page 19-17
–
Components Used, page 19-17
–
Network Diagram, page 19-18
–
Procedures for Layer 2 Path and Mitigation, page 19-19
–
–
Add the Cisco Catalyst 6500 with SNMP as Access Type (Layer 2 only)., page 19-20
–
Add the Cisco 7500 Router with TELNET as the Access Type, page 19-21
–
Verify the Connectivity Paths for Layer 3 and Layer 2, page 19-22
Perform Mitigation, page 19-26
–
You need to have the SNMP community strings and IP addresses for the Layer 2 switches and
routers.
You must have STP (Spanning Tree Protocol) configured correctly on the switches.
a Cisco Catalyst 5000 with SNMP access enabled
a Cisco Catalyst 6500 for Layer 2 with SNMP access enabled
a Cisco 7500 Router with SNMP or TELNET access enabled
a MARS running software Version 2.5.1
Layer 2 Path and Mitigation Configuration Example
User Guide for Cisco Security MARS Local Controller
19-17