Unknown Reporting Device IP

When your event logs contain entries from unknown reporting devices, this usually means that a device is configured to send logs to MARS, but MARS isn't configured to receive them. You might have also simply forgotten to click the Activate button at the upper-right corner of the MARS screen. If you're sure that you've correctly configured MARS to receive logs from a device, but they are still showing up from an unknown reporting device, try activating your changes.

Figure 9-3 shows an example of what your logs look like with an unknown reporting device. Note that these types of logs show up only when you look at raw events. Figure 9-4 shows how to select All Matching Event Raw Messages from the Query page.

Figure 9-3 Unknown Reporting Device IP

'3 [LC: mars-lc/Admin] Query Results - Microsoft Internet Explorer Ifo1 |fx]

File Edit View Favorites Tools Help

!ll

E:18508068, Unknown Oct 26, 5:16508063 Reporting Device 2006

IPg] 1:27:32 AM PDT

Unknown Reporting Device

unknown reporting IP: 10,0.0.101, SNMPV2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False SMI::enterprises.9.2.9.3.1.1.4.1 5 TCP-MIB::tcpConnState.l0.0.0.101.80.10.0.0.7.2705 Positive synReceived SNMPv2-SMI::enterprises.9.2.6.1.1.5.10.0.0.101.80.10.0.0.7.2705 2 SNMPv2-

SMI::enterprises,9,2,6,1,1,2,10,0,0,101,B0,10.0.0,7,2705 313 SNMPv2-SMI::enterprises,9,2,9,2,1,13,4 ""

E:19508047, Unknown Oct 26, S:1B508047 Reporting Device 2006

IP© 1:27:31 AM PDT

Unknown Reporting Device

unknown reporting IP: 10.0.0.101, SNMPv2-SMI:¡enterprises.9 10.0.0.101 SNMPv2- N/A False

SMI:: enterprises, 9,2,9,3,1,1,4,1 5 TCP-MIB:: top Conn State. 10,0,0.101.80,10,0,0,7,2701 Positive synReceived SNMPv2-SMI::enterprises,9,2,6,1,1,5,10,0,0,101,60,10.0.0,7,2701 2 SNMPv2-

SMI::enterprises,9,2,6,1,1,1,10,0,0,101,60,10.0.0,7,2701 403 SNMPv2-

SMI::enterprises,9,2,6,1,1,2,10,0,0,101,60,10.0.0,7,2701 212 SNMPV2-

SMI::enterprises.9.2.9.2.1.19.4 ""

E:18508052, Unknown Oct 26, S:16508052 Reporting Device 2006

IP© 1:27:31 AM PDT

Unknown Reporting Device

Unknown reporting IP: 10,0.0.101, SNMPv2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False

SMI:: enterprises, 9,2,9,3,1,1,2,1 5 TCP-MIB: :tcp Conn State. 10,0,0.101.80,10,0,0,7,2702 Positive synReceived SNMPv2-SMI::enterprises,9,2,6,l,l,5,10,0,0,101,80,10.0.0,7,2702 1 SNMPv2-

SMI::enterprises.9.2.6.1.1.1.10.0.0.101.80.10.0.0.7.2702 403 SNMPV2-

SMI::enterprises.9.2.6.1.1.2.10.0.0.101.80.10.0.0.7.2702 216 SNMPv2-

SMI::enterprises,9,2,9,2,1,18,2 ""

E;18508058, Unknown Oct 26, S:18508058 Reporting Device 2006

IP© 1:27:31 AM PDT

Reporting Device

unknown reporting IP; 10,0.0.101, SNMPv2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False

SMI:¡enterprises,9,2,9,3,1,1,1,1 5 TCP-MIB::tcpConnState.l0,0,0.101.80,10,0,0,7,2703 Positive synReceived SNMPv2-SMI::enterprises.9.2.6.1.1.5.10.0.0.101.80.10.0.0.7.2703 2 SNMPv2-

SMI::enterprises,9,2,6,1,1,1,10,0,0,101,80,10.0.0,7,2703 418 SNMPv2-

SMI::enterprises,9,2,6,1,1,2,10,0,0,101,60,10.0.0,7,2703 274 SNMPv2-

SMI:: enterprises,9,2,9,2,1,13,1 ""

E:1B50B063, Unknown Oct 26, 5:18508063 Reporting Device 2006

IP© 1:27:31 AM PDT

Unknown Reporting Device

unknown reporting IP: 10.0.0.101, SNMPv2-SMI:¡enterprises.9 10.0.0.101 SNMPv2- N/A False

SMI::enterprises.9.2.9.3.1.1.3.1 5 TCP-MIB::tcpConnState.10.0.0.101.80.10.0.0.7.2704 Positive synReceived SNMPv2-SMI::enterprises,9,2,6,1,1,5,10,0,0,101,80,10.0.0,7,2704 2 SNMPv2-

SMI::enterprises,9,2,6,1,1,1,10,0,0,101,80,10.0.0,7,2704 416 SNMPv2-

SMI::enterprises,9,2,6,1,1,2,10,0,0,101,60,10.0.0,7,2704 224 SNMPV2-

SMI::enterprises.9.2.9.2.1.13.3 ""

E:18508026, Unknown Oct 26, S:1B508026 Reporting Device 2006

IP© 1:27:30 AM PDT

Unknown Reporting Device

unknown reporting IP: 10,0.0.101, SNMPv2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False

SMI::enterprises,9,2,9,3,1,1,4,1 5 TCP-MIB::tcpConnState.10,0,0.101.80,10,0,0,7,2697 Positive synReceived SNMPv2-SMI::enterprises,9,2,6,1,1,5,10,0,0,101,80,10.0.0,7,2697 2 SNMPv2-

SMI::enterprises,9,2,6,1,1,1,10,0,0,101,80,10.0.0,7,2697 417 SNMPV2-

SMI::enterprises.9.2.6.1.1.2.10.0.0.101.80.10.0.0.7.2697 1033 SNMPv2-

SMI::enterprises,9,2,9,2,1,18,4 ""

E:13503032, Unknown Oct 26, S:16508032 Reporting Device 2006

IP© 1:27:30 AM PDT

Unknown Reporting

unknown reporting IP; 10,0.0.101, SNMPv2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False

SMI::enterprises,9,2,9,3,1,1,2,1 5 TCP-MIB::tcpConnState.l0,0,0.101.80,10,0,0,7,2698 Positive synReceived SNMPv2-SMI::enterprises.9.2.6.1.1.5.10.0.0.101.80.10.0.0.7.2698 2 SNMPv2-

SMI::enterprises.9.2.6.1.1.1.10.0.0.101.80.10.0.0.7.2698 405 SNMPv2-

SMI::enterprises,9,2,6,1.1.2,10,0,0,101,80,10.0.0,7,2698 310 SNMPv2-

SMI:;enterprises,9,2,9,2,1,13,2 ""

E:13503037, Unknown Oct 26, 5:18508037 Reporting Device 2006

IP© 1:27:30 AM PDT

Unknown Reporting Device

unknown reporting IP: 10,0.0.101, SNMPV2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False

SMI:: enterprises. 9.2.9.3.1.1.1.1 5 TCP-MIB:: top Conn State. 10.0.0.101.80.10.0.0.7.2699 Positive synReceived SNMPv2-SMI::enterprises,9,2,6,1,1,5,10,0,0,101,80,10.0.0,7,2699 2 SNMPv2-

SMI:;enterprises,9,2,6,1,1,1,10,0,0,101,60,10.0.0,7,2699 416 SNMPv2-

SMI:;enterprises,9,2,6,1,1,2,10,0,0,101,80,10.0.0,7,2699 1045 SNMPv2-

SMI:: enterprises,9,2,9,2,1,18,1""

E:18508042, Unknown Oct 26, 3:18508042 Reporting Device 2006

Unknown Reporting

unknown reporting IP: 10,0.0.101, SNMPv2-SMI:¡enterprises,9 10,0,0,101 SNMPv2- N/A False SMI:: enterprises, 9,2,9,3,1,1,3,1 5 TCP-MIB:: top Conn State. 10,0,0.101.80,10,0,0,7,2700 Positive

v

D

lb $ Internet

Figure 9-4 All Matching Event Raw Messages

Figure 9-4 All Matching Event Raw Messages

In this case, it appears that a device with the IP address of 10.0.0.101 is sending Simple Network Management Protocol (SNMP) traps to the MARS appliance. You need to determine the following things to troubleshoot this:

• Should MARS understand the logs?

If you attempt to connect to 10.0.0.101 using some common TCP applications, you can probably determine what type of device it is. You can also try issuing an snmpwalk command from the MARS CLI. If the device listens for SNMP, and you have the correct SNMP community, the CLI offers a lot of information. The following command can help:

snmpwalk -c community_name 10.0.0.101

The snmpwalk command has several available options. To see them all, just enter the command by itself at the CLI.

In this instance, you determine that the host is a Cisco wireless access point. MARS does not know how to understand logs from this device, and you need to create custom parsing rules to handle logs from these types of devices. This is covered in Chapter 11, "CS-MARS Custom Parser."

You might see these logs at other times, though, when you already think the device should be properly configured. Consider an example Cisco IOS Router. This router might have a handful of interfaces, each with its own IP address:

When this device is added to CS-MARS as a monitored device, you probably needed to specify the following two IP addresses:

• One for the access IP—The access IP address is used for MARS to connect to the router for discovery purposes, such as learning the directly connected networks.

• One for the reporting IP—The reporting IP address associates logs with the proper device.

The access IP address should be the IP address that MARS can reach to perform discoveries, and to pull data if that's the reporting method. For simplicity, many organizations use the loopback address. In this case, you might have configured the access IP address to be 192.168.254.1.

Unless otherwise configured, Cisco routers send syslog messages stamped with the IP address of the interface that sends the message. So, unless you've configured it to do differently, the syslog messages are being sent to MARS from one of the other addresses— 10.1.1.1, 10.2.1.1, or 10.3.1.1. If you configured MARS to use 192.168.254.1 as the reporting IP address, syslog messages will appear as "Unknown Reporting Device IP." Even if you entered a different address, if a network issue causes messages to leave the router from a different interface, the messages will still be from an unknown reporting device IP.

On the IOS Router, you need to always specify what IP address to use for syslog messages. If you want continuity, and you've configured the loopback interface for access IP, use the same interface for reporting IP. On the router, enter the following commands in configuration mode:

logging source-interface loopback 0

Obviously, you can substitute the exact interface you want to use. When this router is configured within MARS, make sure that the IP address associated with this source-interface is entered as the reporting address.

NOTE If MARS is receiving NetFlow data from this router or switch, be sure that it is also configured to send from the same source interface. If it is not, all NetFlow data will show up as "Unknown Reporting Device IP" as well.

Continue reading here: Understanding NAC Framework Communications

Was this article helpful?

0 0