Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 53

Security mars local controller
Table of Contents

Advertisement

Chapter 2
Reporting and Mitigation Devices Overview
Consider distinct goals:
Attack detection
Attack detection and mitigation
Regulatory compliance
Full NAC awareness
Identify the devices/feature pairs that overlap on the same network segment, where a choice between
device can reduce duplicity or prioritize device performance
Last, you must consider an event tuning method for your monitoring strategy. How you tune your MARS
affects your overall operational costs proportionally to the number of device of a give type that are
monitored. Essentially, if you have the bandwidth available, we recommend that you tune the events at
the MARS Appliance, which reduces your operational costs by tuning at a single point in the network.
However, if bandwidth is a precious commodity, you may chose to tune the event propagation at the
reporting device level, preventing the events from going onto the network.
Table 2-2
to configure these devices within your network.
78-17020-01
identifies the device types, describes what information they can provide, and recommends how
Selecting the Devices to Monitor
User Guide for Cisco Security MARS Local Controller
2-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents