
Thursday, July 24, 2008
MARS Canned Reports

Monday, July 14, 2008
Tuesday, June 24, 2008
The Cisco Learning Network Launched

Sign up with an account, and you gain access to short CBT style training segments, PDF documents, discussions, career advise, certification information, plus much more.
In relation to Cisco MARS, on the site you will find 2 or 3 great training segments, or Quick Learning Modules as Cisco calls them, as shown below...

In more detail...

I`d recommend, you go check them out!
Friday, June 13, 2008
Cisco MARS 4.3.5 and 5.3.5 Out Now
Anyhow, Cisco have just released MARS 4.3.5 and 5.3.5, so whats new?
Miscellaneous Changes and Enhancements The following changes and enhancements exist in 4.3.5:
•Bug fixes. For the list of resolved issues, see Resolved Caveats - Release 4.3.5.
You can view the Release notes for 4.3.5 HERE, and 5.3.5 HERE.
Friday, May 16, 2008
New Cisco NetPro Forum

"Welcome to the Cisco Networking Professionals Cisco Security MARS Forum. This conversation will provide you the opportunity to discuss the product, solutions and issues surrounding Cisco Security MARS deployments, maintenance and integration. We encourage everyone to share their knowledge and start conversations about topics involving the Cisco Security MARS. Remember, just like in the workplace, be courteous to your fellow forum participants. Please refrain from using disparaging or obscene language or posting advertisements. We encourage you to tell your fellow networking professionals about the site. Dan Bruhn NetPro Community Manager"
You can link straight to the forum HERE.
Wednesday, May 07, 2008
MARS 20,20R and 50 EOL Announced
Full details of this announcment can be found here
Thursday, April 17, 2008
Cisco MARS 4.3.4 and 5.3.4 Out Now
You can find here, the release notes for 4.3.4 and 5.3.4
New Features
As mentioned on an earlier post, the CSM 3.2 Video i created on Demolabs, was done with a 5.34 Beta Code, these features are now possible!
Improved CSM-MARS Linkage. "With Security Manager 3.2 and MARS 4.3.4 and 5.3.4, you can modify access rules generating the MARS event seamlessly from the read-only policy table popup window, which displays all rules associated with an event, by clicking the highlighted access rule number without starting Security Manager separately. Similarly, you can navigate to the signature summary table in Security Manager from MARS events associated with IPS sensors and IOS IPS devices and alter the signature properties. This feature enables you to map a syslog message to the policy that triggered that message and modify it simultaneously, thereby reducing time spent configuring and troubleshooting access rules in large or complex networks.
Additional improved support includes:
–
Support for MARS to launch CSM and authenticate using stored login credentials.
–
Improved support for firewall and IPS policy rule lookups.
–
From Policy Query, you can edit a signature on an event or define a filter on the CSM device to perform device-side tuning.
–
Edit IPS signatures that fired an inspection rule.
–
Edit IPS signatures that fired an inspection rule."
And of course the usual bugfixes.
Tuesday, April 08, 2008
Cisco MARS 6.0
Cisco yesterday released a bulletin and datasheet for the forthcoming Cisco MARS version 6.0You can find the Bulletin HERE, and the Datasheet HERE.
It looks like there are going to be some great new features, i`ll look forward to it!
"New Features
And a sneak of the new supported devices looks interesting.....
Friday, April 04, 2008
New MARS and CSM 3.2 Linkages
Now i managed to wing a beta of this earlier in the year, as there are some great new MARS linkages. I aslo produced a Demo which can be seen HERE, for a Seminar in London. (I`ll add the version with sound next week).

So whats new?
IPS Configuration
Enhanced Cisco Security Manager and MARS integration
– Ability to select syslog messages collected by Cisco Security MARS and launch to that specific rule in the Cisco Security Manager that generated the syslog
– Ability to select a rule in Cisco Security Manager and view historic or real-time syslog messages in Cisco Security MARS
– Ability to select an IPS signature in Cisco Security Manager and view historical or real-time events processed by Cisco Security MARS
– Ability to view IPS events in Cisco Security MARS and launch to that specific IPS signature in Cisco Security Manager. - Source CSM3.2 Bulletin
Finally some screenshots from the Datasheet....




Friday, March 28, 2008
Custom IPS Signature Events
Now events here can be deleted, so i thought i`d try it...
Now i did a quick check on the Custom IPS Signature upload page, to see if anything untoward had happened here...

Great stuff, so to be sure, so i uploaded a second custom parser event....
And sure enough, the event appeared under the Custom Parser Event Types, and thus can be slightly edited like any custom parser event.. (the description edited below)
And these changes do stick, as a quick event query for Cisco IPS6.x events shows.
NB: This is my own findings, and to my knowledge not in the MARS Userguide. So before you go deleting events as above, i`d check with TAC, that you are not going to explode your MARS box or anything :-)





