Configuring Cisco Catios Switch; Enable Netflow Processing In Mars - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Data Enabling Features
To exit enable mode, enter the following command:
Step 5

Configuring Cisco CatIOS Switch

Some Cisco Catalyst switches support a different implementation of NetFlow that is performed on the
supervisor. With the cache-based forwarding model, which is implemented in the Catalyst 55xx running
the Route Switch Module (RSM) and NetFlow Feature Card (NFFC), the RSM processes the first flow
and the remaining packets in the flow are forwarded by the Supervisor. This support is also implemented
in the early versions of the 65xx with MSFC. The deterministic forwarding model used in the 65xx with
MSFC2 do not use NetFlow to determine the forwarding path, the flow cache is only used for statistics
as in the current IOS implementations. In all of these configurations, flow exports arrive from both the
RSM/MSFC and the Supervisor engines as distinct streams.
The router-side running IOS is configured as specified in
Send NetFlow to MARS, page
following commands:
From a user's perspective, the switch is only running IOS when the 65xx is running in Native mode.

Enable NetFlow Processing in MARS

Once you have enabled NetFlow on your routers or switches and you have directed those devices to
publish NetFlow data to the MARS Appliance, you must configure the appliance to process that data.
This configuration involves determining how to store data, as well as identifying which networks you
want to process for anomalous behavior. Both of these options can affect the rate at which MARS can
process events: storing the full event data rather than summary data burdens the system with writing
large volumes of data rather than processing new incoming events. Also, by not specifying a select set
of networks, MARS studies all networks.
Click Admin > System Setup > NetFlow Config Info.
Step 1
User Guide for Cisco Security MARS Local Controller
2-34
exit
set mls flow full
set mls nde version 5
set mls nde <MARS_IP_address> 2055
set mls nde enable
2-32. However, to configure the he CatIOS NetFlow Data Export, use the
Chapter 2
Reporting and Mitigation Devices Overview
Enable Cisco IOS Routers and Switches to
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents