Configuring AAA Devices
Authentication, authorization, and accounting (AAA) devices provide accountability throughout your network, ensuring that valid users are authorized to use the network services they request and providing detailed event logs regarding failures and successes in such requests. The AAA server is a key component in the Network Access Control (NAC) initiative (see Configuring Network Admission Control Features, page 2-42 and Enable NAC-specific Messages, page 3-4). Cisco Secure Access Control Server...
Add and Configure a Qualys Guard Device in MARS
Adding an internal QualysGuard API Server as a reporting device entails identifying the server or appliance from which the reports are pulled and providing credentials that MARS can use to log in to the device to pull the reports. You can specify whether you want to pull saved scan reports that are run on a schedule or whether you want to initiate and retrieve an on-demand scan report. To add a QualysGuard device, follow these steps Step 1 Select Admin > Security and Monitor Devices > Add....
False Positive Confirmation
When investigating incidents, you will invariably come across false positive events. In some cases, firing events are classified automatically by MARS as system-confirmed false positives and unconfirmed false positives. Vulnerability scanning often identifies the false positive events, but at times you must investigate events to determine their validity. To understand the false positive nomenclature and what tasks you are expected to perform within the user interface, we must study the...
Bootstrap the Net Screen Device
To prepare the NetScreen device to be monitored by MARS, follow these steps Step 1 Login to the NetScreen with appropriate username and password. Step 2 In the main screen, on the left hand column click Network > Interfaces. Step 3 Click Edit next to the appropriate interface to configure for MARS to have access to SNMP and Telnet SSH. Step 4 Under Service Options, select one of the following values MARS can only use one of the access methods to perform configuration discovery. This value...
Add a Check Point Primary Management Station to MARS
The primary management station represents one of the following The SmartCenter server in a SmartCenter or SmartCenter Pro installation. A CMA of a Provider-1 or SiteManager-1 installation. Note Check Point 4.1, NG FP1, and NG FP2 devices are not officially supported. They cannot be configured to retrieve configuration information using CPMI. However, they can be configured to retrieve logs using LEA. To configure one of these devices to work with the MARS, leave the Access IP field blank on the...
MARSside Configuration
To add configuration information for the host Step 1 Click Admin > Security and Monitor Devices > Add Step 2 From the Device Type list, select Add SW Security apps on a new host or Add SW security apps on existing host Step 3 Enter the Device Name and IP Addresses if adding a new host. Step 4 Select the Windows from Operation System list Step 6 For this configuration, you must check the Receive host log box Figure 12-6 Windows Web Server Logging mechanisms Figure 12-6 Windows Web Server...
Add an IPS Module to a Cisco Switch or Cisco ASA
You can enable in-line IPS functionality and signature detection in multi-purpose Cisco platforms. You can identify an IDS-M2 running in a Cisco Switch or an ASA-SSM running in a Cisco ASA. To represent either of these modules, you must define the settings for the module as part of the base platform, which must be previously defined under Admin > System Setup > Security and Monitor Devices. To add an IPS module to a Cisco Switch of Cisco ASA, follow these steps Step 1 Click Admin > System...
Specify the Monitored Networks for Cisco IPS or IDS Device Imported from a Seed File
After you import a Cisco IPS or IDS device into MARS using a seed file, you must define the networks that are monitored by that sensor. To define the networks monitored by a sensor, follow these steps Click Admin > System Setup > Security and Monitor Devices. Select the check box next to the Cisco IPS or IDS device that was imported using a seed file. and click Edit. To specify the networks being monitored by the sensor, do one of the following To manually define the networks, select the...
Case Management Overview
The Case Management feature can capture, combine, and preserve user-selected MARS data within a specialized report called a case. The following data can be added to a case Incident device information (source IP address, destination IP address, reporting device) View Case page (the current case can reference another case) Any user can create or alter any case. You can assign a case to a MARS user on the same machine, and can change the status of a case to assigned, resolved, or closed. The...
Select the Access Type for LEA and CPMI Traffic
Check Point devices use special access types for configuration discovery and event log queries. For configuration discovery, the protocol is CPMI. For event log queries, the protocol is LEA. Each of these protocols has specific configurable attributes, including whether to use bulk encryption, what cipher to use, and what port to use for communications. You must understand what the supported settings are so that you can verify the Check Point devices are configured correctly. MARS supports only...
Configure Tacacs Command Authorization for Cisco Routers and Switches
You can use the TACACS+ feature of Cisco Secure ACS to authorize the command sets that MARS is allowed to execute on a reporting device. The use of this feature is not required by MARS. However, if you are using this feature on your routers and switches, you must ensure that MARS is allowed to execute specific commands. Required commands are grouped under two operations configuration retrieval and mitigation. The following commands support configuration retrieval changeto context <...
Edit Discovered Log Servers on a Check Point Primary Management Station
After performing a discovery operation, you must edit each discovered log servers. The purpose of editing this log server is to identify that it is its own log server and to provide the SIC communication settings. To edit a discovered log server, follow these steps Step 1 Under Firewall & Log Server Settings, select the check box next to the desired log server, and click Log Info. Step 3 Specify values for the following fields Reporting IP Enter the IP address of the interface in the log...
Push Method Configure Generic Microsoft Windows Hosts
MARS can treat hosts running Microsoft Windows as reporting devices, monitoring the event log data generated by the host. The host needs to run InterSect Alliance SNARE Agent for Windows, which captures event log data and sends it to MARS. The push method requires four steps 1. Install the SNARE agent on the Microsoft Windows host. For more information, see Install the SNARE Agent on the Microsoft Windows Host, page 10-5. 2. Configure the SNARE agent to forward event data to the MARS Appliance....








