Cisco.Press.User.Guide.for.Cisco.Security.MARS.pdf
(
6638 KB
)
Pobierz
ugLc.book
User Guide for Cisco Security MARS
Local Controller
Release 4.2.x
June 2006
Corporate Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Customer Order Number:
Text Part Number: 78-17020-01
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The following information is for FCC compliance of Class A devices: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant
to part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial
environment. This equipment generates, uses, and can radiate radio-frequency energy and, if not installed and used in accordance with the instruction manual, may cause
harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which case users will be required
to correct the interference at their own expense.
The following information is for FCC compliance of Class B devices: The equipment described in this manual generates and may radiate radio-frequency energy. If it is not
installed in accordance with Cisco’s installation instructions, it may cause interference with radio and television reception. This equipment has been tested and found to
comply with the limits for a Class B digital device in accordance with the specifications in part 15 of the FCC rules. These specifications are designed to provide reasonable
protection against such interference in a residential installation. However, there is no guarantee that interference will not occur in a particular installation.
Modifying the equipment without Cisco’s written authorization may result in the equipment no longer complying with FCC requirements for Class A or Class B digital
devices. In that event, your right to use the equipment may be limited by FCC regulations, and you may be required to correct any interference to radio or television
communications at your own expense.
You can determine whether your equipment is causing interference by turning it off. If the interference stops, it was probably caused by the Cisco equipment or one of its
peripheral devices. If the equipment causes interference to radio or television reception, try to correct the interference by using one or more of the following measures:
• Turn the television or radio antenna until the interference stops.
• Move the equipment to one side or the other of the television or radio.
• Move the equipment farther away from the television or radio.
• Plug the equipment into an outlet that is on a different circuit from the television or radio. (That is, make certain the equipment and the television or radio are on circuits
controlled by different circuit breakers or fuses.)
Modifications to this product not authorized by Cisco Systems, Inc. could void the FCC approval and negate your authority to operate the product.
The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public
domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work,
Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, BPX, Catalyst, CCDA, CCDP,
CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital,
the Cisco Systems logo, Cisco Unity, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink,
Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo,
Networking Academy, Network Registrar,
Packe t
, PIX, Post-Routing, Pre-Routing, ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet,
The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the
United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. (0601R)
User Guide for Cisco Security MARS Local Controller
Copyright © 2006 Cisco Systems, Inc. All rights reserved.
CONTENTS
Preface
xix
Introduction
xix
The MARS Appliance
xix
The MARS Web Interface
xix
About This Manual
xx
Obtaining Documentation
xxi
Cisco.com
xxi
Documentation DVD
xxi
Ordering Documentation
xxii
Documentation Feedback
xxii
Cisco Product Security Overview
xxii
Reporting Security Problems in Cisco Products
xxiii
Obtaining Technical Assistance
xxiii
Cisco Technical Support Website
xxiii
Submitting a Service Request
xxiv
Definitions of Service Request Severity
xxiv
Obtaining Additional Publications and Information
xxv
CHAPTER
1
STM Task Flow Overview
1-1
Checklist for Provisioning Phase
1-2
Checklist for Monitoring Phase
1-9
Strategies for Monitoring, Notification, Mitigation, Remediation, and Audit
1-16
Appliance-side Tuning Guidelines
1-17
Device Inventory Worksheet
1-18
User Role Worksheet
1-20
CHAPTER
2
Reporting and Mitigation Devices Overview
2-1
Levels of Operation
2-1
Selecting the Devices to Monitor
2-2
Understanding Access IP, Reporting IP, and Interface Settings
2-8
Access IP
2-9
Reporting IP
2-9
Interface Settings
2-10
User Guide for Cisco Security MARS Local Controller
78-17020-01
iii
Contents
Selecting the Access Type
2-10
Configure SNMP Access for Devices in MARS
2-11
Configure Telnet Access for Devices in MARS
2-11
Configure SSH Access for Devices in MARS
2-12
Configure FTP Access for Devices in MARS
2-12
Bootstrap Summary Table
2-12
Adding Reporting and Mitigation Devices
2-16
Add Reporting and Mitigation Devices Individually
2-17
Edit a Device
2-18
Upgrade the Device Type to a Newer Version
2-18
Delete a Device
2-19
Delete All Displayed Reporting Devices
2-20
Add Multiple Reporting and Mitigation Devices Using a Seed File
2-20
Devices that Require Custom Seed Files
2-21
Devices that Require Updates After the Seed File Import
2-21
Seed File Header Columns
2-21
Load Devices From the Seed File
2-24
Adding Reporting and Mitigation Devices Using Automatic Topology Discovery
2-25
Verify Connectivity with the Reporting and Mitigation Devices
2-26
Discover and Testing Connectivity Options
2-26
Run a Reporting Device Query
2-27
Activate the Reporting and Mitigation Devices
2-27
Data Enabling Features
2-28
Layer 2 Discovery and Mitigation
2-29
Networks for Dynamic Vulnerability Scanning
2-29
Select a Network for Scanning
2-30
Create a Network IP Address for Scanning
2-30
Create a Network IP Range for Scanning
2-30
Understanding NetFlow Anomaly Detection
2-30
How MARS Uses NetFlow Data
2-31
Guidelines for Configuring NetFlow on Your Network
2-32
Enable Cisco IOS Routers and Switches to Send NetFlow to MARS
2-32
Configuring Cisco CatIOS Switch
2-34
Enable NetFlow Processing in MARS
2-34
Host and Device Identification and Detail Strategies
2-36
Configuring Layer 3 Topology Discovery
2-36
Add a Community String for a Network
2-37
Add a Community String for an IP Range
2-37
Add Valid Networks to Discovery List
2-38
User Guide for Cisco Security MARS Local Controller
iv
78-17020-01
Contents
Remove Networks from Discovery List
2-38
Discover Layer 3 Data On Demand
2-38
Scheduling Topology Updates
2-39
Schedule a Network Discovery
2-39
To edit a scheduled topology discovery
2-40
To delete a scheduled topology discovery
2-40
To run a topology discovery on demand
2-41
Configuring Resource Usage Data
2-41
Configuring Network Admission Control Features
2-42
Integrating MARS with 3
rd
-Party Applications
2-43
Forwarding Alert Data to 3
rd
-Party Syslog and SNMP Servers
2-43
MARS MIB Format
2-43
Relaying Syslog Messages from 3rd-Party Syslog Servers
2-44
Configure Syslog-ng Server to Forward Events to MARS
2-44
Configure Kiwi Syslog Server to Forward Events to MARS
2-45
Add Syslog Relay Server to MARS
2-45
Add Devices Monitored by Syslog Relay Server
2-46
CHAPTER
3
Configuring Router and Switch Devices
3-1
Cisco Router Devices
3-1
Enable Administrative Access to Devices Running Cisco IOS 12.2
3-1
Enable SNMP Administrative Access
3-2
Enable Telnet Administrative Access
3-2
Enable SSH Administrative Access
3-2
Enable FTP-based Administrative Access
3-2
Configure the Device Running Cisco IOS 12.2 to Generate Required Data
3-3
Enable Syslog Messages
3-3
Enable SNMP RO Strings
3-3
Enable NAC-specific Messages
3-4
Enable SDEE for IOS IPS Software
3-6
Add and Configure a Cisco Router in MARS
3-6
Cisco Switch Devices
3-9
Enable Communications Between Devices Running CatOS and MARS
3-9
Enable SNMP Administrative Access
3-10
Enable Telnet Administrative Access
3-10
Enable SSH Administrative Access
3-10
Enable FTP-based Administrative Access
3-10
Configure the Device Running CatOS to Generate Required Data
3-11
Enable SNMP RO Strings on CatOS
3-11
User Guide for Cisco Security MARS Local Controller
78-17020-01
v
Plik z chomika:
yaroor
Inne pliki z tego folderu:
Cisco.Press.Penetration.Testing.and.Network.Defense.chm
(14976 KB)
Cisco.Press.IS.IS.Network.Design.Solutions.chm
(3096 KB)
Lab3-5.exe
(112 KB)
Practice_Lab4_Section_2.pdf
(31 KB)
Practice_Lab5_Section_3.pdf
(1392 KB)
Inne foldery tego chomika:
----- ebooki
----- ebooki(1)
----- Czarnobyl
----- Mapy Sztabowe 1-50000
----- jednostki specjalne
Zgłoś jeśli
naruszono regulamin