Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 565

Security mars local controller
Table of Contents

Advertisement

Appendix D
System Rules and Reports
This report ranks hosts by the total number of events detecting scanning activity directed to that
host. Scans involve activities such as searching for alive hosts, open services on such hosts and
detecting host configuration and application settings.
Activity: Scans - Top Destinations.
Activity: Scans - Top Destinations
Activity: Scans - Top Sources.
This report ranks an attack sources by the total number of events detecting scanning activity for
certain services. Scans involve activities such as searching for alive hosts, open services on such
hosts and detecting host configuration and application settings.
Activity: Scans - Top Sources.
Activity: Scans - Top Sources
Activity: Security Posture: Healthy - Top Users.
This report lists the users in a HEALTHY Security Posture State. A Healthy security posture implies
that the posture of the host is up to date, policy compliant and does not need attention.
Activity: Security Posture: Healthy - Top Users.
Activity: Security Posture: Healthy - Top Users
Activity: Security Posture: NAC - Top NADs and Tokens.
This report displays the Network Access Devices (NADs) handling Network Admission Control
transcations along with the tokens assigned by each of them.
Activity: Security Posture: NAC - Top NADs and Tokens.
This report displays the Network Access Devices (NADs) handling Network Admission Control
transcations along with the tokens assigned by each of them.
Activity: Security Posture: NAC - Top NADs.
This report ranks the network access devices (NADs) handling Network Admission Control
transcations.
Activity: Security Posture: NAC - Top NADs.
This report ranks the network access devices (NADs) handling Network Admission Control
transcations.
Activity: Security Posture: NAC - Top Tokens.
This report shows the network wide distribution of NAC tokens. The possible token values are
HEALTHY, CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is
excluded since it is an intermediate state.
Activity: Security Posture: NAC - Top Tokens.
This report shows the network wide distribution of NAC tokens. The possible token values are
HEALTHY, CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is
excluded since it is an intermediate state.
Activity: Security Posture: NAC Agentless - Top Hosts.
This report captures the distribution of NAC tokens for end hosts that do not have Cisco Trust Agent
(CTA) software. In this case, the posture validation is done either locally by the Network Access
Device or via the Audit Server. The possible NAC tokens values in this report are HEALTHY,
CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is excluded
since it is an intermediate state.
Activity: Security Posture: NAC Agentless - Top Hosts.
78-17020-01
User Guide for Cisco Security MARS Local Controller
List of System Reports
D-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents