<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-34995790</id><updated>2012-02-17T00:42:27.454Z</updated><category term='CS-MARS 4.3.2'/><category term='MARS FSCK'/><category term='NetWitness'/><category term='MARS Alternative Review'/><category term='SNARE'/><category term='Incident Escalation'/><category term='CS-MARS Case Management'/><category term='Netpro Package Sharing.'/><category term='Cisco Job'/><category term='Cisco MARS 4.3.2 / 5.3.2'/><category term='CS-MARS Vulnerabiltiy'/><category term='ReguLazy'/><category term='Cisco MARS 5.3.6'/><category term='CS-MARS Deployment Guide'/><category term='nProbe'/><category term='Traffic Anomalies'/><category term='CS-MARS Unlock'/><category term='CS-MARS 4.3.1'/><category term='Oracle Database'/><category term='CS-MARS Upgrade'/><category term='VPN3005'/><category term='CS-MARS Priveon Paper'/><category term='Cisco NAC'/><category term='MARS Analysis'/><category term='InMon Sflow Toolkit'/><category term='MARS Custom Parser'/><category term='MARS Troubleshooting'/><category term='Cisco MARS Custom Parser'/><category term='Cisco MARS 4.3'/><category term='CME'/><category term='Cisco Mars Netflow'/><category term='Netflow Performance Analysis'/><category term='AccelOps Review'/><category term='Cisco NAC Appliance Custom Parser'/><category term='MARS SNMP v3'/><category term='Rules'/><category term='Session'/><category term='Network Response Blog'/><category term='NSEL with MARS'/><category term='XP Firewall'/><category term='Snort Sensors'/><category term='CS-MARS Demos'/><category term='Ironport'/><category term='NFS'/><category term='Cisco MARS Implementation Service'/><category term='McAfee ePO'/><category term='MARS 25'/><category term='Cisco Routers for the Desperate'/><category term='Book Review Securing the Borderless Network'/><category term='Cisco SAFE'/><category term='Netflow'/><category term='Cisco MARS 5.3.3'/><category term='CS-MARS Gen2 Appliances'/><category term='PNOS Directory'/><category term='NAC'/><category term='GC and GCm.'/><category term='CS-MARS 5.3.2 Wireless Support'/><category term='Tipping Point and Cisco MARS'/><category term='Cisco MARS Blog'/><category term='Real Time Events'/><category term='Qualys'/><category term='Cisco Techwise TV'/><category term='Custom Parsing Gothcha'/><category term='SecureVue'/><category term='Priveon'/><category term='CS-MARS Ask the Expert'/><category term='CS-MARS Sizing'/><category term='Cisco MARS Training'/><category term='Cisco MARS IPS 6 Dynamic Updates'/><category term='6.0.3 Update'/><category term='Cisco MARS Netpro Parser Sharing'/><category term='Cisco MARS 6 Patch'/><category term='CS-MARS 4.2.7'/><category term='MARS 6.0.4'/><category term='Cisco MARS 5.3.4'/><category term='Cisco IPS with MARS Part 3'/><category term='Cisco MARS 6.0.2'/><category term='Network Flow Analysis Book Review'/><category term='CS-MARS 6.0'/><category term='Storage'/><category term='CS-MARS US DST Changes'/><category term='Demolabs'/><category term='200'/><category term='Cisco Press'/><category term='MARS 20R EOL'/><category term='CS-MARS Reporting'/><category term='Accelops'/><category term='Cisco MARS 6.0.1 Available Now'/><category term='Incident Views'/><category term='Cisco MARS 5.3.5'/><category term='CVE-2009-2977'/><category term='Cisco Book Review'/><category term='Ask the Expert CS-MARS'/><category term='CS-MARS 5.2.x'/><category term='642-544'/><category term='Foundstone'/><category term='Cisco MARS'/><category term='Tcpdump'/><category term='CS-MARS'/><category term='MARS Archive'/><category term='Satisnet'/><category term='802.1X'/><category term='MARS Training'/><category term='PCI Compliance'/><category term='Cisco Security Manager'/><category term='Cisco Book Review LAN Switch Security'/><category term='Cisco MARS Vulnerability'/><category term='Calence'/><category term='CS-MARS Book'/><category term='Custom IPS Signatures Editing'/><category term='Guest Post: Anton Chuvakin'/><category term='Fortinet Custom Parser'/><category term='CCO Checker'/><category term='25R and 55'/><category term='URL Filtering'/><category term='Cisco MARS 6.0.6'/><category term='CS-MARS 4.2.5'/><category term='Cisco MARS 4.3.3'/><category term='Cisco MARS Exam'/><category term='CS-MARS Raw Event Query Limits'/><category term='Archiving Remote Storage Capacity'/><category term='CS-MARS 4.2.6'/><category term='CS-MARS User Group'/><category term='CS-MARS Archiving'/><category term='CS-MARS Guard and Detector'/><category term='Exploring Cisco MARS'/><category term='pndbusage'/><category term='Cisco MARS 6.0.4'/><category term='SIEMLink'/><category term='Cisco VPN Concentrator'/><category term='MARS Blog'/><category term='CS-MARS 4.2.4'/><category term='Cisco MARS Tips'/><category term='Cisco Guard and Detector Custom Parser'/><category term='TechWise TV'/><category term='Cisco SIEM Deployment Guide'/><category term='MARS FIPS'/><category term='Cisco NAC Appliance Blog'/><category term='IDS/IPS'/><category term='Incident'/><category term='Cisco MARS 6.0.3'/><category term='Custom IPS Signatures with Cisco MARS'/><category term='CS-MARS Updates'/><category term='CS-MARS Custom Parser'/><category term='Trend Micro DCS integration with MARS'/><category term='CS-MARS Blogs'/><category term='Cisco ASA Secure Logging'/><category term='Cisco MARS 6.0'/><category term='Cisco MARS EoS'/><category term='Cisco IPS with MARS'/><category term='MAC Address Report'/><category term='Cisco ASA VPN Usage with MARS'/><category term='PCI Data Security Standard'/><category term='MARS 6.0.3'/><category term='Cisco Security MARS'/><category term='Mitigation'/><category term='CS-MARS Python Scripts'/><category term='Cisco Learning Network'/><category term='Cisco MARS 6.1.3'/><category term='Cisco Security Manager 3.2'/><category term='MARS EOL 100'/><category term='CS-MARS Host Logging'/><category term='EIQNetworks'/><category term='CS-MARS Rules'/><category term='MARS Models EOL'/><category term='Windows Services for UNIX'/><category term='NFS Archive Failure'/><category term='MARS Rules'/><category term='Cisco Emulation'/><category term='Cisco MARS Netpro Forum'/><category term='Finjan Custom Parser'/><category term='Raw Events'/><category term='Cisco MARS 6.0.8'/><category term='Cisco MARS 4.3.6'/><category term='IronPort Seminar'/><category term='Cisco MARS 6.1.2'/><category term='Security Threat Mitigation and Response'/><category term='CSM'/><category term='MARS'/><category term='Cisco MARS 4.2.8'/><category term='CS-MARS Checkpoint Reporting Device'/><category term='Cisco MARS 6.1.1'/><category term='Cisco MARS 4.3.5'/><category term='Cisco MARS Compliance Reports'/><category term='Custom Signatures'/><category term='100e'/><category term='Cisco IOS IPS'/><category term='Cisco MARS Sflow'/><category term='MARS InfoSecurity Magazine'/><category term='AccelOps 10 Reasons'/><category term='MARS 50 EOL'/><category term='CSMARS'/><category term='SAN Reading Room Paper'/><category term='Cisco ASA Botnet Traffic Filter'/><category term='Search'/><category term='MARS 20 EOL'/><category term='Events and Sessions'/><category term='CS-MARS Windows Events'/><category term='CS-MARS Training'/><category term='MARS Users and Groups'/><category term='CS-MARS Compliance Reporting'/><category term='Cisco MARS v6'/><category term='Cisco MARS 4.3.4'/><category term='CS-MARS AAA with Microsoft IAS Server'/><category term='Queries'/><category term='Netfarmers'/><category term='Self-Defending Networks'/><category term='Define Services'/><category term='Cisco MARS 6.0.7'/><category term='CS-MARS Incident Severity'/><category term='Cisco MARS User Group'/><title type='text'>The Unofficial MARS Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default?start-index=101&amp;max-results=100'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>190</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34995790.post-4463344749838288065</id><published>2012-01-06T23:36:00.000Z</published><updated>2012-01-06T23:36:28.374Z</updated><title type='text'>Cisco MARS 6.1.4 Released</title><summary type='text'>Cisco released MARS 6.1.4 late December.

The release notes can be viewed HERE

Signature updates as follows.....









In terms of disclosure, i am also pleased to announce I have recently joined the AccelOps EMEA team, as a Technical Consultant. A great product with a big future.
 
Happy New Year for 2012.

</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4463344749838288065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4463344749838288065' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4463344749838288065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4463344749838288065'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2012/01/cisco-mars-614-released.html' title='Cisco MARS 6.1.4 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Yhhm-X8FuGA/TweDucxBcNI/AAAAAAAABfg/lx0R7wK4qGE/s72-c/update1.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8868437200824475475</id><published>2011-10-07T21:59:00.001Z</published><updated>2011-10-07T22:01:56.328Z</updated><title type='text'>Book Review: Practical Packet Analysis, 2nd Ed</title><summary type='text'>Book Review: Practical Packet Analysis, 2nd Edition
Author: Chris Sanders
Published By: no starch press
ISBN: 978-1-59327-266-1


Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems


"It's easy enough to install Wireshark and begin capturing packets off the wire--or from the air. But how do you interpret those packets once you've captured them? And how can those </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8868437200824475475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8868437200824475475' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8868437200824475475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8868437200824475475'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/10/book-review-practical-packet-analysis.html' title='Book Review: Practical Packet Analysis, 2nd Ed'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3265939367846601098</id><published>2011-09-04T21:20:00.000Z</published><updated>2011-09-04T21:20:17.117Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.1.3'/><title type='text'>Cisco MARS 6.1.3 Released</title><summary type='text'>If you are still using MARS, you will be pleased to hear Cisco released MARS version 6.1.3 a couple of weeks ago.

No new features, which is not surprising, being end of sale, but a few bugs have been fixed.

Some signature updates, as in the table below, but you may also notice some devices are now over a year out of date!



New Features
This release includes contains no new features. It is a </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3265939367846601098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3265939367846601098' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3265939367846601098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3265939367846601098'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/09/cisco-mars-613-released.html' title='Cisco MARS 6.1.3 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-8CqL6PrWS_g/TmPq6EnJ8NI/AAAAAAAABfc/5FrC6KFn0Uk/s72-c/mars6_1_3_Sigs.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6605449124494881409</id><published>2011-06-28T16:43:00.000Z</published><updated>2011-06-28T16:43:40.266Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS EoS'/><title type='text'>Beyond the Cisco MARS End of Sale Date.</title><summary type='text'>



I note via, the number of emails and blog visitors, that the search for Cisco MARS replacements, is starting to hot up, now the End-of-Sale Date, has officially passed.
Thats not to say, i have had a few emails recently, telling me that their local partner, is offering them a good deal, on a new MARS appliance!
So have you started your replacement search?
</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6605449124494881409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6605449124494881409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6605449124494881409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6605449124494881409'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/06/beyond-cisco-mars-end-of-sale-date.html' title='Beyond the Cisco MARS End of Sale Date.'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-OOx_raT-xXk/TgoBqdCDJsI/AAAAAAAABfY/h20vDK5kJLc/s72-c/cisco_eos_blog.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-713825787213086238</id><published>2011-04-13T17:31:00.000Z</published><updated>2011-04-13T17:31:39.998Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Guest Post: Anton Chuvakin'/><title type='text'>Guest Post: How to Replace a SIEM?</title><summary type='text'>How to Replace a SIEM
by Dr. Anton Chuvakin



Ouch! That “Venus” SIEM  appliance that  we got with routers has finally croaked. That piece of PHP brilliance that  pre-pre-previous security engineer wrote has been buried under the thick pile of  XML. That managed SIEM provider has annoyed us one last time.
What do the above situations have in common? The unfortunate time to  replace your SIEM has</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/713825787213086238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=713825787213086238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/713825787213086238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/713825787213086238'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/04/guest-post-how-to-replace-siem.html' title='Guest Post: How to Replace a SIEM?'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-W8LEwWU5fvk/TaXX2A_HANI/AAAAAAAABfU/Pu78I7fyUiY/s72-c/chuvakin.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-23662117813142785</id><published>2011-03-06T21:54:00.001Z</published><updated>2011-03-07T07:41:28.115Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='AccelOps 10 Reasons'/><title type='text'>AD: 10 Reasons for Migrating from MARS to AccelOps</title><summary type='text'>Sponsor Advertisement 

AccelOps, the integrated datacenter and        cloud monitoring company, today announced a Competitive Upgrade Package with “10        Reasons for Migrating from CS-MARS to AccelOps” exclusively for Cisco CS-MARS security        appliance customers and resellers. This is in response to the market demand from the        current CS-MARS user community and resellers seeking a</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/23662117813142785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=23662117813142785' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/23662117813142785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/23662117813142785'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/03/ad-10-reasons-for-migrating-from-mars.html' title='AD: 10 Reasons for Migrating from MARS to AccelOps'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh6.googleusercontent.com/-wWJXAMalSxY/TXFvhjC2ETI/AAAAAAAABfQ/tIV6g5Mz1as/s72-c/accelops_10_reasons.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8936135392267260643</id><published>2011-03-04T21:07:00.000Z</published><updated>2011-03-04T21:07:55.605Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.1.2'/><title type='text'>Cisco MARS 6.1.2 Released</title><summary type='text'>Looks like Cisco released MARS 6.1.2 towards the end of February.

Obviously no new features, but signature updates, and a couple of fixes.

New Features 
   This release includes contains no new features. It is a release dedicated to issue resolution. 
You can read the release notes HERE 

</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8936135392267260643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8936135392267260643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8936135392267260643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8936135392267260643'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/03/cisco-mars-612-released.html' title='Cisco MARS 6.1.2 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh3.googleusercontent.com/-aOy3dU0fZCs/TXFUTTTsQrI/AAAAAAAABfM/3weTbMVBBLg/s72-c/mars_6_1_2.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7775184899127286360</id><published>2011-02-21T11:10:00.000Z</published><updated>2011-02-21T11:10:06.868Z</updated><title type='text'>February Update</title><summary type='text'>WIth the Cisco MARS End of Life dates, being finally announced at the end of last year, I am starting to see more enquires to the blog around replacement products.

So I have lined up some new content for the blog, including some great guest articles, and I am still looking for more.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7775184899127286360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7775184899127286360' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7775184899127286360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7775184899127286360'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2011/02/february-update.html' title='February Update'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6632352136088089072</id><published>2010-12-04T17:15:00.000Z</published><updated>2010-12-04T17:15:45.205Z</updated><title type='text'>Cisco MARS End of Life - Official</title><summary type='text'>Well its official, Cisco have announced the End of Life for Cisco MARS.

"Cisco announces the end-of-sale and end-of life  dates for the Cisco Security Monitoring, Analysis, and Response System.  The last day to order the affected product(s) is June 3, 2011."

You can read the official End of Life/End of Sales notification HERE. 

The end of an Era, for probably the largest deployed SIEM tool out</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6632352136088089072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6632352136088089072' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6632352136088089072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6632352136088089072'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/12/cisco-mars-end-of-life-official.html' title='Cisco MARS End of Life - Official'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7276755621176200005</id><published>2010-11-29T15:45:00.000Z</published><updated>2010-11-29T15:45:36.284Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco SIEM Deployment Guide'/><title type='text'>Cisco SIEM Deployment Guide</title><summary type='text'>November updates, a mixture of old and new news. 
Cisco has made a few SIEM partner announcements in their efforts to bolster their Secure Borderless Network initiative as deftly referenced by Sean Martin in CIO Insight.

The new rather flashy SIEM Deployment Guide  also references how Cisco is working with some other SIEM vendors.
Also see how others are working with SIEMS such as NetWitness .

</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7276755621176200005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7276755621176200005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7276755621176200005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7276755621176200005'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/11/cisco-siem-deployment-guide.html' title='Cisco SIEM Deployment Guide'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/TPPJhqdclTI/AAAAAAAABfA/YvXV0nQDiZM/s72-c/cisco_siem_deployment_guide.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3445631408637178781</id><published>2010-11-12T20:24:00.001Z</published><updated>2010-11-13T18:36:21.914Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS InfoSecurity Magazine'/><title type='text'>Where on Earth is MARS?</title><summary type='text'>Found this interesting article in a new infosecurity magazine, on the demise of Cisco MARS, entitled "Where on Earth is MARS?"
The article references MARS past, and surmises on the demise of Cisco MARS, and continues to relay some of the negative sentiment from a handful of analysts in the past year.

I have to say that many people though appreciate and still utilize the many innovations and </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3445631408637178781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3445631408637178781' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3445631408637178781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3445631408637178781'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/11/where-on-earth-is-mars.html' title='Where on Earth is MARS?'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/TN7ZypI7YlI/AAAAAAAABe0/OZKWFBr0HgM/s72-c/where_mars.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2890642311603469747</id><published>2010-10-28T13:37:00.001Z</published><updated>2010-10-28T13:38:12.922Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.1.1'/><title type='text'>Cisco MARS 6.1.1 Released</title><summary type='text'>Cisco have released MARS Version 6.1.1

You can view the release notes HEREChanges and Enhancements ASA 8.2.2 Botnet Traffic Filter  The ASA BTF feature was enhanced in ASA 8.2.2 to add blacklist actions  including blocking functionality to Dynamic Filter, as well as  additional attributes. MARS Release 6.1.1 supports these enhanced BTF  attributes: •Parses the new BTF-specific syslogs that </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2890642311603469747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2890642311603469747' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2890642311603469747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2890642311603469747'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/10/cisco-mars-611-released.html' title='Cisco MARS 6.1.1 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1829023168691906199</id><published>2010-09-01T14:04:00.000Z</published><updated>2010-09-01T14:04:07.876Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.8'/><title type='text'>Cisco MARS 6.0.8 Now Available</title><summary type='text'>A couple of weeks, out of date due to my holidays, but Cisco have released MARS 6.0.8

You can review the release notes HERE

There are no new product enhancements, but this release has updated Vendor Signatures, for Cisco (and Non Cisco Devices), as shown below....

New Vendor Signatures 
 The following table describes the most recent signatures supported for each product or technology:
    
</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1829023168691906199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1829023168691906199' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1829023168691906199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1829023168691906199'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/09/cisco-mars-608-now-available.html' title='Cisco MARS 6.0.8 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-9081536731861894469</id><published>2010-08-12T08:11:00.000Z</published><updated>2010-08-12T08:11:31.031Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Network Flow Analysis Book Review'/><title type='text'>Book Review: Network Flow Analysis</title><summary type='text'>
Book Review: Network Flow Analysis
Author: Michael W.Lucas
Published By: no starch press
ISBN: 1593272030
"Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data."
If you have ever read any of Michael W.Lucas' other books, you will know you are in for a humorous and entertaining read.
</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/9081536731861894469/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=9081536731861894469' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9081536731861894469'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9081536731861894469'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/08/book-review-network-flow-analysis.html' title='Book Review: Network Flow Analysis'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4949949654771598502</id><published>2010-07-30T21:38:00.001Z</published><updated>2010-11-29T15:29:16.028Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='AccelOps Review'/><title type='text'>Review: AccelOps - Part 2</title><summary type='text'>In the first part of the AccelOps review, I gave a quick overview of its many features.

In Part 2, I'd like to dig a bit deeper, and cover information that serves both security and network teams – specifically dashboards, rules, logical business groups, virtual appliance and a quick and simple MARS comparison.

Dashboards
One of the items where AccelOps excels is dashboards, and there are plenty</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4949949654771598502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4949949654771598502' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4949949654771598502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4949949654771598502'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/07/review-accelops-part-2.html' title='Review: AccelOps - Part 2'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ohceiKUYGG8/TFM_o1vG4zI/AAAAAAAABdg/IKeeJXxLTvk/s72-c/1.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6564267880653203530</id><published>2010-07-27T09:38:00.001Z</published><updated>2010-07-27T11:23:00.014Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco SIEM Deployment Guide'/><title type='text'>New Cisco SIEM Deployment Guide</title><summary type='text'>Cisco have released, the Security Information Event Management (SIEM) Deployment Guide, as part of the Smart Business Architecture, Borderless Networks for Enterprise Organizations.

Personally this looks like a first step, Cisco is making to work with other SIEM vendors, to handle non Cisco and Cisco devices.
"This guide is for security operations personnel in enterprise organizations who want </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6564267880653203530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6564267880653203530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6564267880653203530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6564267880653203530'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/07/new-cisco-siem-deployment-guide.html' title='New Cisco SIEM Deployment Guide'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/TE7BfUE0hjI/AAAAAAAABdY/rwocARIQOA4/s72-c/siem.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-9137805037557215165</id><published>2010-07-21T11:34:00.010Z</published><updated>2010-07-21T11:58:02.801Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NetWitness'/><category scheme='http://www.blogger.com/atom/ns#' term='SIEMLink'/><title type='text'>SIEMLink with MARS</title><summary type='text'>Although not exactly new news, you may not know, that one of the complaints from the security community regarding MARS, and to be honest most SIEMS, is the lack of real session data, or raw packets, for incident response.



Now one of the hottest products around, in this arena is NetWitness.
"NetWitness Investigator is the award-winning interactive threat analysis application of the NetWitness </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/9137805037557215165/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=9137805037557215165' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9137805037557215165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9137805037557215165'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/07/siemlink-with-mars.html' title='SIEMLink with MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ohceiKUYGG8/TEbPsN7Y8oI/AAAAAAAABco/BqCt1uf6uMg/s72-c/siemlink_mars.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5631287465092460125</id><published>2010-07-09T16:26:00.001Z</published><updated>2010-08-31T19:09:00.770Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS Alternative Review'/><category scheme='http://www.blogger.com/atom/ns#' term='Accelops'/><title type='text'>Review: Accelops - Part One</title><summary type='text'>


What options have you got, if you are looking to replace or upgrade your MARS appliance or other SIEM/logging solution?

A lot has changed in the SIEM space, since Cisco released the Cisco Monitoring Analysis and Response System, around early 2005.

MARS was one of the first products to collect, normalize and correlate event logs from all the major security vendors, systems and netflow, and </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5631287465092460125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5631287465092460125' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5631287465092460125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5631287465092460125'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/07/review-accelops-part-one.html' title='Review: Accelops - Part One'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/TDc1QJKytaI/AAAAAAAABbY/WsIAxEaeUQI/s72-c/allinone-aointegratedarchitecture.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5809022159523303717</id><published>2010-07-08T20:47:00.003Z</published><updated>2010-07-09T08:32:27.910Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS Blog'/><title type='text'>MARS Blog Update</title><summary type='text'>You may of noticed that  Gartner left Cisco MARS out of the SIEM Magic Quadrant for 2010 this year. 
And although hard to find, Cisco did come out and say MARS will in future will concentrate on Cisco only devices, and critical host OS. (And then recently released 6.07 with support for Windows 2008)
Cisco have also recently announced Cisco Security Agent has gone End of Sale, but there have been </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5809022159523303717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5809022159523303717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5809022159523303717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5809022159523303717'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/07/mars-blog-update.html' title='MARS Blog Update'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3840300502756286386</id><published>2010-06-02T16:29:00.001Z</published><updated>2010-06-02T21:41:01.123Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Book Review Securing the Borderless Network'/><title type='text'>Book Review: Securing the Borderless Network</title><summary type='text'>Book: Securing the Borderless Network
Published By: Cisco Press
Author: Tom Gillis

"Today’s new Web 2.0, virtualization, mobility, telepresence, and collaborative applications offer immense potential for enhancing productivity and competitive advantage. However, they also introduce daunting new security issues, many of which are already being exploited by cybercriminals. Securing the Borderless </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3840300502756286386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3840300502756286386' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3840300502756286386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3840300502756286386'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/06/book-review-securing-borderless-network.html' title='Book Review: Securing the Borderless Network'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-134811898751695271</id><published>2010-05-26T20:15:00.000Z</published><updated>2010-05-26T20:15:36.511Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.7'/><title type='text'>Cisco MARS 6.0.7 Now Available</title><summary type='text'>Cisco have released MARS version 6.0.7

You can read the release notes HERE


Changes and EnhancementsThe following enhancement exists in Cisco Security MARS, Release 6.0.7:•Support for Windows 2008—Cisco Security MARS provides agent based, native log support for Windows 2008 server hosts. Users can send syslog to CS-MARS by installing a Snare agent on their Windows 2008 server hosts.•Support for</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/134811898751695271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=134811898751695271' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/134811898751695271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/134811898751695271'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/05/cisco-mars-607-now-available.html' title='Cisco MARS 6.0.7 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1776726143346947891</id><published>2010-05-11T16:39:00.000Z</published><updated>2010-05-11T16:39:37.146Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco ASA Secure Logging'/><title type='text'>Cisco ASA Secure Logging and MARS</title><summary type='text'>Doug McKillip, a Global Knowledge Instructor, has created a white paper, "Using Syslog Effectively for Security Troubleshooting".

Part of this whitepaper, details using The Cisco ASA Secure Logging feature, over TCP to Cisco MARS.


You can get access to this whitepaper HERE.

Further info on secure logging and the ASA, can be found here, in the  Cisco ASA 8.2 CLI Guide.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1776726143346947891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1776726143346947891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1776726143346947891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1776726143346947891'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/05/cisco-asa-secure-logging-and-mars.html' title='Cisco ASA Secure Logging and MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/S-mHp-etB3I/AAAAAAAABa8/WRKRrMjg210/s72-c/mars_secure_syslog.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8700880878947141973</id><published>2010-04-21T20:47:00.002Z</published><updated>2010-04-21T20:50:02.079Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS SNMP v3'/><title type='text'>MARS Support for SNMP V3</title><summary type='text'>Rather than re-invent the wheel, there is a good write up on the new SNMP v3 feature, in MARS 6.0.6 on the Global Knowledge Blog.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8700880878947141973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8700880878947141973' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8700880878947141973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8700880878947141973'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/04/mars-support-for-snmp-v3.html' title='MARS Support for SNMP V3'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1858155415890320359</id><published>2010-03-24T16:04:00.003Z</published><updated>2010-03-24T16:14:51.292Z</updated><title type='text'>Fancy a new Job?</title><summary type='text'>I have been busy recently on a couple of new demos on making the most of MARS, by interfacing with some 3rd party products, unfortunately these are not finished yet.But in the meantime I thought i would let you know about some jobs that are going at the United Health Group.Recession -what recession? !!!Network  Manager – United Health Group    UHG has multiple network  operations positions open </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1858155415890320359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1858155415890320359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1858155415890320359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1858155415890320359'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/03/fancy-new-job.html' title='Fancy a new Job?'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3499621948221058322</id><published>2010-01-26T09:07:00.002Z</published><updated>2010-01-26T09:13:24.155Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.6'/><title type='text'>Cisco MARS 6.0.6 Now Available</title><summary type='text'>Release Notes for 6.0.6 are available HEREMiscellaneous Changes and Enhancements   The following changes and enhancements exist in MARS, Release 6.0.6:   •SNMP v. 3.0 Support—Leveraging a secure communication protocol between MARS and Cisco security enforcement devices, customers can be assured that they are securely mitigating attacks and configuring and managing devices. SNMPv3 support enables </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3499621948221058322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3499621948221058322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3499621948221058322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3499621948221058322'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2010/01/cisco-mars-606-now-available.html' title='Cisco MARS 6.0.6 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7159110603165868716</id><published>2009-11-13T16:30:00.003Z</published><updated>2009-11-13T16:44:53.259Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-2977'/><title type='text'>CVE-2009-2977</title><summary type='text'>Thanks to an eagle eyed reader, (though it is a couple of months old now), if you are running 6.0.4 and earlier, there is an Vulnerability when MARS is configured to pull Windows Event Logs."The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7159110603165868716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7159110603165868716' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7159110603165868716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7159110603165868716'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/11/cve-2009-2977.html' title='CVE-2009-2977'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8301831164664157944</id><published>2009-11-05T21:12:00.002Z</published><updated>2009-11-05T21:23:29.298Z</updated><title type='text'>No Updates for Non Cisco Devices?</title><summary type='text'>There has been plenty of rumours recently regarding MARS, and its support for Non Cisco Devices,  more so,  over the last couple of days...Whether its Gartner a few days ago, or MARS competitors, like Nitro putting out releases yesterday,  (and I`d fully expect the others to follow)I noticed an official Business Unit response, in the Netpro Forums......"October 30, 2009 Cisco response to Gartner </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8301831164664157944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8301831164664157944' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8301831164664157944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8301831164664157944'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/11/no-updates-for-non-cisco-devices.html' title='No Updates for Non Cisco Devices?'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5120476175074624066</id><published>2009-11-05T20:52:00.002Z</published><updated>2009-11-05T21:01:14.485Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Routers for the Desperate'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Book Review'/><title type='text'>Book Review: Cisco Routers for the Desperate, 2nd Ed</title><summary type='text'>"Cisco Routers for the Desperate, 2nd Edition is designed to be read once and left alone until something breaks. When it does, you'll have everything you need to know in one easy-to-follow guidebook." Cisco Routers for the Desperate, 2nd Edition, by Michael W.Lucas, condenses all you need to know about Cisco routers, and some switching down to a mere 125 pages.  Now your not going to pass your </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5120476175074624066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5120476175074624066' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5120476175074624066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5120476175074624066'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/11/book-review-cisco-routers-for-desperate.html' title='Book Review: Cisco Routers for the Desperate, 2nd Ed'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SvM7U17hBmI/AAAAAAAABa0/8sj3MyKuQKU/s72-c/cisco_routers.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-180900306752061084</id><published>2009-11-02T14:06:00.002Z</published><updated>2009-11-02T14:08:21.514Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS FIPS'/><title type='text'>MARS 6.0.5 FIPS PCI Card Notes</title><summary type='text'>As you may of read in the release notes for MARS 6.0.5, a FIPS PCI Card is available for the MARS 110RYou can read details here</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/180900306752061084/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=180900306752061084' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/180900306752061084'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/180900306752061084'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/11/mars-605-fips-pci-card-notes.html' title='MARS 6.0.5 FIPS PCI Card Notes'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8343874278582303085</id><published>2009-10-20T13:14:00.001Z</published><updated>2009-10-20T13:15:18.795Z</updated><title type='text'>MARS 6.0.5 Released</title><summary type='text'>Release notes here: 6.0.5 Miscellaneous Changes and Enhancements   The following changes and enhancements exist in:   •FIPS 140-2 Level 2 Compliance for the MARS 110R—Some customers, especially those in the federal market, require secure appliance communications to use government approved encryption technologies and provide tamper protection. When used in conjunction with a Cisco FIPS 140-2 Level</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8343874278582303085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8343874278582303085' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8343874278582303085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8343874278582303085'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/10/mars-605-released.html' title='MARS 6.0.5 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-698088336500562692</id><published>2009-08-05T09:53:00.003Z</published><updated>2009-08-05T09:58:15.480Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS 6.0.4'/><title type='text'>MARS 6.0.4 Revised Release Notes</title><summary type='text'>To clear any confusion!, although there has been no announcement, the release notes have been revised for MARS Version 6.0.4Upgrade to 6.0.4No important notes exist for the 6.0.4 upgrade.As you will see, no mention of the "last software release for the CS-MARS 100, 100e, 200, GC, and GCm appliances.":-)</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/698088336500562692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=698088336500562692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/698088336500562692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/698088336500562692'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/08/mars-604-revised-release-notes.html' title='MARS 6.0.4 Revised Release Notes'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1396058166949556720</id><published>2009-08-04T15:34:00.004Z</published><updated>2009-08-04T15:45:12.025Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='GC and GCm.'/><category scheme='http://www.blogger.com/atom/ns#' term='100e'/><category scheme='http://www.blogger.com/atom/ns#' term='200'/><category scheme='http://www.blogger.com/atom/ns#' term='MARS EOL 100'/><title type='text'>MARS 6.0.4 Confusion, Explaination</title><summary type='text'>Earlier from the release notes, there was a notice regarding 6.0.4 and supported versions.Upgrade to 6.0.4   The 6.0.3 release, distributed in April 2009, was the last software release for the CS-MARS 100, 100e, 200, GC, and GCm appliances. Therefore, you cannot apply the 6.0.4 release to these appliance models. For a full list of supported appliance models, see Supported Hardware. BUT, if you </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1396058166949556720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1396058166949556720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1396058166949556720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1396058166949556720'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/08/mars-604-confusion-explaination.html' title='MARS 6.0.4 Confusion, Explaination'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5354861656154697610</id><published>2009-08-04T12:16:00.004Z</published><updated>2009-08-04T12:28:47.923Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.4'/><title type='text'>Cisco MARS 6.0.4 Now Available</title><summary type='text'>Thanks to Csaba for pointing out to me, that Cisco have released MARS version 6.0.4Surprisingly with some of the rumours out there at the moment, there are some new features in this release, and not just signature updates for the supported products.You can check out the release notes HERE.So apart from some cosmetic changes, here is what is new... New Device Support   The 6.0.4 release of MARS </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5354861656154697610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5354861656154697610' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5354861656154697610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5354861656154697610'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/08/cisco-mars-604-now-available.html' title='Cisco MARS 6.0.4 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SngnLFu_MtI/AAAAAAAABas/cKmcGPj4xms/s72-c/asa_mars_6_0_4.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5800954333617007928</id><published>2009-05-28T10:42:00.004Z</published><updated>2009-05-28T11:00:20.842Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco ASA Botnet Traffic Filter'/><category scheme='http://www.blogger.com/atom/ns#' term='Ironport'/><title type='text'>ASA Botnet  Traffic Filter Syslogs</title><summary type='text'>"The Cisco® ASA Botnet Traffic Filter complements existing endpoint security solutions by monitoring network ports for rogue activity and detecting infected internal endpoints sending command and control traffic back to a host on the Internet. The Botnet Traffic Filter database accurately and reliably identifies command and control traffic, as well as the domains or hosts receiving the </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5800954333617007928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5800954333617007928' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5800954333617007928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5800954333617007928'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/05/asa-botnet-traffic-filter-syslogs.html' title='ASA Botnet  Traffic Filter Syslogs'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/Sh5q-jjJnoI/AAAAAAAABac/S8yEmvt0cEg/s72-c/asa_botnet.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1755614416134656862</id><published>2009-05-15T09:05:00.001Z</published><updated>2009-05-15T09:07:53.202Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='6.0.3 Update'/><title type='text'>Update on 6.0.3 Patch</title><summary type='text'>Thanks to Bob Lin, for an update on the 6.0.3 patch I mentioned yesterday.Incidentally, the 6.0.3 patch and patch readme can both be downloaded from the MARS Miscellaneous CCO site:http://www.cisco.com/cgi-bin/tablebuild.pl/cs-mars-misc. It is only required if you encounter one of those two bugs.Regards,Bob LinCS-MARS Release Manager and Escalation Engineer</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1755614416134656862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1755614416134656862' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1755614416134656862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1755614416134656862'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/05/update-on-603-patch.html' title='Update on 6.0.3 Patch'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-206997324341394269</id><published>2009-05-14T08:51:00.002Z</published><updated>2009-05-14T08:56:25.010Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS 6.0.3'/><title type='text'>6.0.3 Patch Available</title><summary type='text'>Thanks to Jeremy Wood in the MARS User Group for pointing out there is a patch available for MARS release 6.0.3"I was noticing that I had a bunch of Drop rules that were nottriggering correctly after upgrading to 6.0.3 and in my quest for asolution ran across a patch here:Looks like it fixes the following problems:CSCsz14701 - some drop rules do not drop packets after 602 to 603 upgradeCSCsz22056</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/206997324341394269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=206997324341394269' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/206997324341394269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/206997324341394269'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/05/603-patch-available.html' title='6.0.3 Patch Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6513259256932658041</id><published>2009-05-04T21:22:00.002Z</published><updated>2009-05-04T21:24:13.582Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS Troubleshooting'/><title type='text'>MARS Troubleshooting Technotes</title><summary type='text'>I notice Cisco have added a new doc, under the MARS configuration examples section on Cisco.com, on Troubleshooting.Worth a read for any newbies.You can view this HERE.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6513259256932658041/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6513259256932658041' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6513259256932658041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6513259256932658041'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/05/mars-troubleshooting-technotes.html' title='MARS Troubleshooting Technotes'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6858741024450613319</id><published>2009-04-27T12:27:00.003Z</published><updated>2009-04-27T12:35:37.206Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Satisnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Job'/><title type='text'>Cisco Security Specialist Required</title><summary type='text'>In today’s recession hit world, companies world wide are letting staff go, and making redundancies.At Satisnet, the UK’s leading Security Partner, we are actually hiring!I`m looking to add another member to our Security Consulting Practice, and that could well be you.If think you meet the following requirements....Have a Cisco CCSP or CCIE, or are at least working towards these qualificationsA </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6858741024450613319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6858741024450613319' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6858741024450613319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6858741024450613319'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/04/cisco-security-specialist-required.html' title='Cisco Security Specialist Required'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8396795344972426514</id><published>2009-04-24T12:58:00.003Z</published><updated>2009-04-24T13:01:19.421Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco SAFE'/><title type='text'>New Cisco SAFE Reference Guides</title><summary type='text'>A new set of Cisco SAFE Reference Guides, have just been released. These were very successful a few years ago, and it looks like they have been brought upto date.You can view the MARS Safe Doc HERE, and the full set of documents HERE.Worth a read. :-)</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8396795344972426514/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8396795344972426514' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8396795344972426514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8396795344972426514'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/04/new-cisco-safe-reference-guides.html' title='New Cisco SAFE Reference Guides'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SfG3iPP2jpI/AAAAAAAABaU/EODUDbcut7M/s72-c/cisco_safe.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3529972809827396784</id><published>2009-04-07T09:53:00.002Z</published><updated>2009-04-07T09:55:15.469Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.3'/><title type='text'>Cisco MARS 6.0.3 Now Available</title><summary type='text'>Cisco have released MARS version 6.0.3 Miscellaneous Changes and Enhancements   The following changes and enhancements exist in :   •Credential Automation—Save administrative time by updating many Cisco device credentials in a single operation rather than touching each device definition in MARS. Using a seed file to re-import devices that are already defined in MARS, users can update some </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3529972809827396784/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3529972809827396784' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3529972809827396784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3529972809827396784'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/04/cisco-mars-603-now-available.html' title='Cisco MARS 6.0.3 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-869084375362544542</id><published>2009-04-03T10:22:00.002Z</published><updated>2009-04-03T10:23:07.932Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS'/><title type='text'>No News</title><summary type='text'>Sorry for the delay in posts recently, but since there has been no new updates to MARS since mid December, i aint got much to write about!Any ideas let me know......................</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/869084375362544542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=869084375362544542' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/869084375362544542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/869084375362544542'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/04/no-news.html' title='No News'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8615423886403645376</id><published>2009-02-26T21:59:00.003Z</published><updated>2009-02-26T22:03:27.083Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco IOS IPS'/><title type='text'>Cisco IOS IPS with MARS</title><summary type='text'>There is a demo on Cisco.com, on using IOS IPS configured with Cisco Configuration Professional and MARS.You can view this HERE.*************Want to advertise HERE? Make me an offer.......**************</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8615423886403645376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8615423886403645376' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8615423886403645376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8615423886403645376'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/02/cisco-ios-ips-with-mars.html' title='Cisco IOS IPS with MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-417959342090922294</id><published>2009-02-24T12:20:00.005Z</published><updated>2009-02-24T12:29:01.190Z</updated><title type='text'>Cisco NAC Appliance 4.5 Parser Available</title><summary type='text'>Looks like, there is now a draft DSF package for NAC Appliance 4.5 been uploaded to the MARS Package Sharing Exchange.But my only grievance with this exchange, is that there is no where to tell users what the import passwords are.Hence one reason, i put the Lancope Stealthwatch 5.7 Package, as an import password of: lancopeSo if anyone knows the import pass for the NAC Appliance 4.5 parser, </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/417959342090922294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=417959342090922294' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/417959342090922294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/417959342090922294'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/02/cisco-nac-appliance-45-parser-available.html' title='Cisco NAC Appliance 4.5 Parser Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SaPmxnM-jeI/AAAAAAAABaE/dinFSzkPBZY/s72-c/nac4_5.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6170263103845541330</id><published>2009-02-17T12:05:00.003Z</published><updated>2009-02-17T12:12:06.366Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Netpro Package Sharing.'/><title type='text'>Cisco Netpro MARS Package Sharing</title><summary type='text'>The Netpro Package Sharing facility on Cisco.com, is now open to the public. (previously it hidden, and only truely available by your MARS appliance)Lets hope this will now encourage people to start sharing rules, reports and of course custom parsers.Appologies for the lack of postings recently, i`ve been concentrating on getting the Unoffical Cisco Security Agent Blog up and running. Hopefully i</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6170263103845541330/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6170263103845541330' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6170263103845541330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6170263103845541330'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/02/cisco-netpro-mars-package-sharing.html' title='Cisco Netpro MARS Package Sharing'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ohceiKUYGG8/SZqoarLIasI/AAAAAAAABZw/aQRkCdqQb1I/s72-c/mars_parsers.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3078167689305302554</id><published>2009-01-28T09:58:00.001Z</published><updated>2009-01-28T10:00:23.128Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Training'/><title type='text'>Global Knowledge MARS Training</title><summary type='text'>I see lots of visitors to the MARS blog, looking for training. Jim Thomas, MARS Course Director for Global Knowledge, gives us an insight into their offering below...."In a truly Self Defending Network, detection and mitigation occur automatically. Alerts come in after the fact for forensic purposes, but all in all, we rest assured that when we leave our business day behind us, the network is </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3078167689305302554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3078167689305302554' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3078167689305302554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3078167689305302554'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/01/global-knowledge-mars-training.html' title='Global Knowledge MARS Training'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/SYAsg75Kj2I/AAAAAAAABZg/jcMVfIx3HuY/s72-c/gk.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1679952462894395466</id><published>2009-01-05T16:38:00.003Z</published><updated>2009-01-05T16:45:42.166Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NSEL with MARS'/><title type='text'>NetFlow Secure Event Logging (NSEL) with MARS</title><summary type='text'>Happy new Year!You may of heard that the newer ASA 5580`s supported Netflow Secure Event Logging.Now i`ve never seen this in action, but it may be of interest to see this is supported by MARS..Check out the links Below...Configuring NSEL for MARS on the ASA 5580Configuring and Using NetFlow Secure Event Logging (NSEL) Cisco ASA 5580 Implementation Note for NetFlow CollectorsOn a further note, i </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1679952462894395466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1679952462894395466' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1679952462894395466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1679952462894395466'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2009/01/netflow-secure-event-logging-nsel-with.html' title='NetFlow Secure Event Logging (NSEL) with MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-9064808909914335886</id><published>2008-12-17T17:35:00.002Z</published><updated>2008-12-17T17:37:28.591Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.2'/><title type='text'>Cisco MARS 6.0.2 Now Available</title><summary type='text'>CS-MARS Upgrade Package for 6.0.2 (3102) Cisco MARS 6.0.2 has been released, with the obvious 3rd Party Signature updates, and a few bug fixes. A summary of the updated Cisco devices support is below...Miscellaneous Changes and Enhancements   The following changes and enhancements exist in 6.0.2:   •Cisco ASA 8.0.4 support   •Cisco ASA 8.1.2 support   •Cisco IPS 6.1 supportYou can check out the </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/9064808909914335886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=9064808909914335886' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9064808909914335886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/9064808909914335886'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/12/cisco-mars-602-now-available.html' title='Cisco MARS 6.0.2 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5270440012173427831</id><published>2008-11-25T15:53:00.006Z</published><updated>2008-11-25T16:05:32.592Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS Rules'/><title type='text'>Email Alerts based on the Incident Severity</title><summary type='text'>I got asked the question the other day, if it was possible only to receive an email, when Incidents were of the RED Severity.Now if you think about it, its an option to get an email when an Incident is created, but you cannot be selective if this was RED, AMBER or GREEN.Now there is a noddy way to achieve this, if you want to go the trouble, and this would be based on duplicating rules...Consider</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5270440012173427831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5270440012173427831' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5270440012173427831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5270440012173427831'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/11/email-alerts-based-on-incident-severity.html' title='Email Alerts based on the Incident Severity'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SSwgWxPwSQI/AAAAAAAABUc/0tTB9_zcgmE/s72-c/rule.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3856514702366453675</id><published>2008-11-05T14:33:00.000Z</published><updated>2008-11-05T14:35:26.989Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6 Patch'/><title type='text'>Cisco MARS 6.01 Patch Available</title><summary type='text'>Cisco have released a patch, CS-MARS 6.0.1 3070, for users on MARS 6.0.1 release (3066).Who should apply the Patch1) Users who have the following devices reporting to MARS: Cisco Switch IOS, Cisco IPS- User has a Cisco Switch-IOS configured to send syslogs to the MARS (CSCsu94548)- User downloaded and installed MARS IPS packages S333, S351, or S354 from http://www.cisco.com/cgi-bin/tablebuild.pl/</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3856514702366453675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3856514702366453675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3856514702366453675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3856514702366453675'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/11/cisco-mars-601-patch-available.html' title='Cisco MARS 6.01 Patch Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ohceiKUYGG8/SRGu_8BgnwI/AAAAAAAABUU/3Imr-61zN_Y/s72-c/mars6_patch.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-624350021814907450</id><published>2008-10-31T15:52:00.005Z</published><updated>2008-10-31T16:20:41.944Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Netpro Parser Sharing'/><title type='text'>Netpro Package Sharing</title><summary type='text'>For those, that have not yet upgraded to the latest V6 code of MARS, (and i know thats quite a few!), here are some screenshots of the new Parser Sharing Forum.With V4/5 and below, there was the concept of the Custom Parser. Beginning with MARS 6.0, these new custom parsing features are referred to as the Device Support Framework (DSF).With DSF you can quickly add support for new device types, </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/624350021814907450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=624350021814907450' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/624350021814907450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/624350021814907450'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/10/netpro-package-sharing.html' title='Netpro Package Sharing'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ohceiKUYGG8/SQstoD_sm3I/AAAAAAAABUE/P04mivMcV8s/s72-c/package_sharing.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7879681989688841919</id><published>2008-09-18T08:36:00.003Z</published><updated>2008-09-18T08:44:37.816Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0.1 Available Now'/><title type='text'>MARS 6.0.1 Now Available</title><summary type='text'>Cisco MARS 6.0.1 is now available to download from CCO.Documentation Links below....Device Configuration Guide for Cisco Security MARS, Release 6.x Cisco Security MARS Initial Configuration and Upgrade Guide, 6.X Cisco Security MARS Hardware Installation and Maintenance Guide 6.XUser Guide for Cisco Security MARS Local and Global Controllers, Release 6.xCisco Security MARS Command Reference, 6.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7879681989688841919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7879681989688841919' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7879681989688841919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7879681989688841919'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/09/mars-601-now-available.html' title='MARS 6.0.1 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ohceiKUYGG8/SNIUDd7CCQI/AAAAAAAAA8s/MDpKu5pY6fo/s72-c/6_0_1_upgrade.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5924302197111074409</id><published>2008-09-17T09:00:00.002Z</published><updated>2008-09-17T09:04:26.803Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS v6'/><title type='text'>Cisco MARS 6.0.1 Release Notes</title><summary type='text'>Thanks to a post in the Cisco MARS User Group , the Release notes for MARS 6.0.1 are now available on Cisco.comA snippet below, shows the updated on box, vendor sigs....You can also find, a Migrating Data from Cisco Security MARS 4.x to 6.0.1, document HERE.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5924302197111074409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5924302197111074409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5924302197111074409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5924302197111074409'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/09/cisco-mars-601-release-notes.html' title='Cisco MARS 6.0.1 Release Notes'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ohceiKUYGG8/SNDHrBYUq1I/AAAAAAAAA8k/7ow8mB3GYwk/s72-c/6_0_1_supported_sigs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8902450416995590743</id><published>2008-09-17T08:37:00.003Z</published><updated>2008-09-17T08:40:15.341Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ask the Expert CS-MARS'/><title type='text'>ASK THE EXPERT - CS-MARS</title><summary type='text'>Not sure if anyone has seen this, but there is a current "Ask the Expert" series, running on the Netpro forums, on MARS.Looking at the discussions, it looks like MARS 6.0 will be out by the end of September.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8902450416995590743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8902450416995590743' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8902450416995590743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8902450416995590743'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/09/ask-expert-cs-mars.html' title='ASK THE EXPERT - CS-MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ohceiKUYGG8/SNDCI6PVgQI/AAAAAAAAA8c/2G_4wOmOMYk/s72-c/mars_netpri.bmp' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5840796702134751609</id><published>2008-09-11T08:50:00.003Z</published><updated>2008-09-11T09:01:15.333Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fortinet Custom Parser'/><title type='text'>Fortinet Custom Parsing</title><summary type='text'>Sorry for the lack of posts recently, i`ve been busy....With work....Studying for the CCIE!I got marriedWent on Honeymoon to Mexico and the USA.And apart from the above, i`ve been patiently waiting for MARS v6 to be released!So whats new?Well thanks to everyone who has sent me the link to the article below... Sebastian from the Firewall Guru Blog has posted an article, on how to create a custom </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5840796702134751609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5840796702134751609' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5840796702134751609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5840796702134751609'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/09/fortinet-custom-parsing.html' title='Fortinet Custom Parsing'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ohceiKUYGG8/SMjd2iF0Z8I/AAAAAAAAA8U/kqBblONmAVA/s72-c/fortinet.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2686472709454762094</id><published>2008-08-22T08:25:00.003Z</published><updated>2008-08-22T08:35:05.920Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 5.3.6'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.3.6'/><title type='text'>Cisco MARS 4.3.6 and 5.3.6 released</title><summary type='text'>Cisco have yesterday released MARS 4.3.6 and 5.3.6.Theres no new features in this release, but a major fix.The following changes and enhancements exist in 4.3.6 and 5.3.6:   •Resolution of issue introduced in x.3.4 release. The driver for the x.3.6 release is to correct CSCsr47032, a defect introduced in x.3.4 that results in the database gradually filling up with unneeded audit logs. This defect</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2686472709454762094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2686472709454762094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2686472709454762094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2686472709454762094'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/08/cisco-mars-436-and-536-released.html' title='Cisco MARS 4.3.6 and 5.3.6 released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5298026271774572588</id><published>2008-07-24T14:31:00.004Z</published><updated>2008-07-24T14:34:53.615Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Compliance Reports'/><title type='text'>MARS Canned Reports</title><summary type='text'>I know I have posted on this before, but newer readers may not have seen this document.On the Cisco Learning Network, there is a PDF Doc, that lists the various compliance requirements, and the reports in Cisco MARS that can help meet that objective.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5298026271774572588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5298026271774572588' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5298026271774572588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5298026271774572588'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/07/mars-canned-reports.html' title='MARS Canned Reports'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/SIiSiR9-3OI/AAAAAAAAA8M/9hFYJQdlTTY/s72-c/canned_reports.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1925202280120496642</id><published>2008-07-14T08:45:00.003Z</published><updated>2008-07-14T08:49:48.647Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Emulation'/><title type='text'>Emulation Links Added</title><summary type='text'>I`ve added a new links section named "Cisco Emulation" to the blog.As you may know i`m currently studying for the CCIE Security. If your in the same boat as me, there are some great sites out there you should be aware of. Go check them out!</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1925202280120496642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1925202280120496642' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1925202280120496642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1925202280120496642'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/07/emulation-links-added.html' title='Emulation Links Added'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/SHsSM-Aeb0I/AAAAAAAAA78/zdn3wwUL08M/s72-c/emulation_links.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1311325611756740125</id><published>2008-06-24T15:40:00.004Z</published><updated>2008-06-24T16:04:00.621Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Learning Network'/><title type='text'>The Cisco Learning Network Launched</title><summary type='text'>Cisco has launched the new Cisco Learning Network. This is a great new online community of Cisco learning professionals, looking to gain training and support on the various Cisco Qualifications and Technologies.Sign up with an account, and you gain access to short CBT style training segments, PDF documents, discussions, career advise, certification information, plus much more.In relation to Cisco</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1311325611756740125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1311325611756740125' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1311325611756740125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1311325611756740125'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/06/cisco-learning-network-launched.html' title='The Cisco Learning Network Launched'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/SGEY1cYTWBI/AAAAAAAAA7k/elHm_D9DekU/s72-c/learning_network.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8193688372200516734</id><published>2008-06-13T10:20:00.006Z</published><updated>2008-06-13T10:27:27.916Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.3.5'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 5.3.5'/><title type='text'>Cisco MARS 4.3.5 and 5.3.5 Out Now</title><summary type='text'>Appologies for the lack of posts recently, i`ve been overloaded with PIX/VPN3000 to ASA Migrations, and Cisco Security Manager jobs.Anyhow, Cisco have just released MARS 4.3.5 and 5.3.5,  so whats new? Miscellaneous Changes and Enhancements   The following changes and enhancements exist in 4.3.5: •Update to intrusion prevention, and intrusion detection, and vulnerability assessment signature sets</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8193688372200516734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8193688372200516734' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8193688372200516734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8193688372200516734'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/06/cisco-mars-435-and-535-out-now.html' title='Cisco MARS 4.3.5 and 5.3.5 Out Now'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/SFJKnIt7ZPI/AAAAAAAAA7c/9Qdj0wCwbNs/s72-c/4_3_5_New_Sigs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7275936586364627662</id><published>2008-05-16T08:02:00.002Z</published><updated>2008-05-16T08:05:28.257Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Netpro Forum'/><title type='text'>New Cisco NetPro Forum</title><summary type='text'>Cisco have introduced a new section dedicated to MARS on the Netpro Forums on Cisco.com"Welcome to the Cisco Networking Professionals Cisco Security MARS Forum. This conversation will provide you the opportunity to discuss the product, solutions and issues surrounding Cisco Security MARS deployments, maintenance and integration. We encourage everyone to share their knowledge and start </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7275936586364627662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7275936586364627662' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7275936586364627662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7275936586364627662'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/05/new-cisco-netpro-forum.html' title='New Cisco NetPro Forum'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/SC1ADTu9OGI/AAAAAAAAA7U/xW8WBHTc7eA/s72-c/mars_netpro.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5528697553373437412</id><published>2008-05-07T08:41:00.001Z</published><updated>2008-05-07T08:43:14.204Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS 50 EOL'/><category scheme='http://www.blogger.com/atom/ns#' term='MARS 20R EOL'/><category scheme='http://www.blogger.com/atom/ns#' term='MARS 20 EOL'/><title type='text'>MARS 20,20R and 50 EOL Announced</title><summary type='text'>"Cisco® announces the end-of-sale and end-of life dates for the Cisco Security Monitoring, Analysis and Response System (MARS) 20R/20/50 Appliances. The last day to order the affected product(s) is July 31, 2008."Full details of this announcment can be found here</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5528697553373437412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5528697553373437412' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5528697553373437412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5528697553373437412'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/05/mars-2020r-and-50-eol-announced.html' title='MARS 20,20R and 50 EOL Announced'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-5536087371481812323</id><published>2008-04-17T15:18:00.003Z</published><updated>2008-04-17T15:51:11.581Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 5.3.4'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.3.4'/><title type='text'>Cisco MARS 4.3.4 and 5.3.4 Out Now</title><summary type='text'>Cisco MARS Versions 4.3.4 for Gen1 Appliances, and 5.3.4 for Gen2 Appliances has just been released.You can find here, the release notes for 4.3.4 and 5.3.4New FeaturesAs mentioned on an earlier post, the CSM 3.2 Video i created on Demolabs, was done with a 5.34 Beta Code, these features are now possible! Improved CSM-MARS Linkage. "With Security Manager 3.2 and MARS  4.3.4 and 5.3.4, you can </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/5536087371481812323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=5536087371481812323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5536087371481812323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/5536087371481812323'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/04/cisco-mars-434-and-534-out-now.html' title='Cisco MARS 4.3.4 and 5.3.4 Out Now'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/SAdu_OxUG6I/AAAAAAAAA6k/VsrCxDTNhBA/s72-c/5_3_4_sigs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7825564074939467569</id><published>2008-04-08T15:23:00.005Z</published><updated>2008-04-08T20:50:03.479Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS 6.0'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 6.0'/><title type='text'>Cisco MARS 6.0</title><summary type='text'>Cisco yesterday released a bulletin and datasheet for the forthcoming Cisco MARS version 6.0You can find the Bulletin HERE, and the Datasheet HERE.It looks like there are going to be some great new features, i`ll look forward to it!"Cisco Security MARS Release 6.0 will be included in all appliances purchased beginning approximately August 2008. Current Cisco Security MARS customers who have valid</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7825564074939467569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7825564074939467569' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7825564074939467569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7825564074939467569'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/04/cisco-mars-60.html' title='Cisco MARS 6.0'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R_uOvHOoVvI/AAAAAAAAA6U/W2MKqvv61pA/s72-c/bulletin_6.jpg' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4784988493036311915</id><published>2008-04-04T15:11:00.006Z</published><updated>2008-04-04T15:33:04.873Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Security Manager 3.2'/><title type='text'>New MARS and CSM 3.2 Linkages</title><summary type='text'>Some of you may of noticed Cisco Security Manager 3.2 was released at the end of March.Now i managed to wing a beta of this earlier in the year, as there are some great new MARS linkages. I aslo produced a Demo which can be seen HERE, for a Seminar in London. (I`ll add the version with sound next week).I`m not completely sure what will work today, as I created the demo using an early MARS 5.34 </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4784988493036311915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4784988493036311915' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4784988493036311915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4784988493036311915'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/04/new-mars-and-csm-32-linkages.html' title='New MARS and CSM 3.2 Linkages'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/R_ZHn3OoVpI/AAAAAAAAA5k/IYDVp7af_A8/s72-c/csm_demo.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2958586786043959121</id><published>2008-03-28T11:32:00.010Z</published><updated>2008-03-28T12:17:01.738Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Custom IPS Signatures Editing'/><title type='text'>Custom IPS Signature Events</title><summary type='text'>In Part 3 of the Cisco IPS Custom Signatures Article, after discussion with someone i cant remember,I made the following statement...."An important note to remember is that once you define a Custom IPS sig, this cannot be deleted, but can be overwritten."Now this is not strictly true, as i have found, whilst doing some custom parser work. When defining event parsers i noticed that an event was in</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2958586786043959121/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2958586786043959121' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2958586786043959121'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2958586786043959121'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/custom-ips-signature-events.html' title='Custom IPS Signature Events'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R-zbo3OoViI/AAAAAAAAA4s/OnvT7NFEiG8/s72-c/one.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2017786412844077011</id><published>2008-03-25T16:58:00.004Z</published><updated>2008-03-25T17:22:00.430Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Custom Parsing Gothcha'/><title type='text'>Custom Parsing Gotcha</title><summary type='text'>I`m in the process of finishing a custom parser, to share with the user group. Have a look at the image above, everything looks fine, the message has been successfully parsed.But on closer inspection the Matched Strings and Parsed Strings for the Source and Destination Addresses are different.Why is this? Well in this particular case, the device sending the syslog to MARS was "zero-padding" the </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2017786412844077011/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2017786412844077011' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2017786412844077011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2017786412844077011'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/custom-parsing-gotcha.html' title='Custom Parsing Gotcha'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_ohceiKUYGG8/R-kyKXOoVhI/AAAAAAAAA4k/wHUYb1Bv_8k/s72-c/parser_errors2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-389458348532969840</id><published>2008-03-14T16:46:00.007Z</published><updated>2008-03-14T17:15:53.410Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='URL Filtering'/><title type='text'>Firewall Issues</title><summary type='text'>Sometimes i get asked, about the Rule "System Rule: Operational Issue: Firewall", and what kinds of events would trigger this."This rule detects operational errors (e.g. bad network connectivity, failover errors, internal software/hardware errors) reported by a firewall - this may indicate that the firewall is not functioning properly."Well one such event, is "URL Server not responding".In this </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/389458348532969840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=389458348532969840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/389458348532969840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/389458348532969840'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/firewall-issues.html' title='Firewall Issues'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/R9qugdbiVJI/AAAAAAAAA4E/tLWq8baXGAA/s72-c/URL+Server.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7640472695160566221</id><published>2008-03-10T15:39:00.003Z</published><updated>2008-03-10T15:56:50.415Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='25R and 55'/><category scheme='http://www.blogger.com/atom/ns#' term='MARS 25'/><title type='text'>MARS 25, 25R and 55 on the Horizon</title><summary type='text'>I noticed on CDW that pricing for the new Cisco MARS 25, 25R and 55 models was available.•CS-MARS-25R-K9•CS-MARS-25-K9•CS-MARS-55-K9To my knowledge these new 1U, Gen2 based models are not yet released, but looking on Cisco.com, information on the models is starting to slip out...The information above, taken from the 5.3 install guide. Interesting to note that the 55 model, has a field replaceable</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7640472695160566221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7640472695160566221' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7640472695160566221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7640472695160566221'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/mars-25-25r-and-55-on-horizon.html' title='MARS 25, 25R and 55 on the Horizon'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R9VWkNbiVHI/AAAAAAAAA30/N2weGS_-TRg/s72-c/mars_25_55_specs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1664199990117828597</id><published>2008-03-04T16:51:00.004Z</published><updated>2008-03-04T17:07:44.091Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Custom IPS Signatures with Cisco MARS'/><title type='text'>Custom IPS Signatures with Cisco MARS Demo</title><summary type='text'>Ok as promised the link to a new Demo i`ve created for Demolabs.co.uk now with sound! :-)This demo created for a seminar, shows creating a custom signature in Cisco IPS, and the process for MARS to understand the event, with a little scenario around remote users downloading confidential files.Note: The demo does not imply that custom signatures should be used wisely on the network for this </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1664199990117828597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1664199990117828597' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1664199990117828597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1664199990117828597'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/custom-ips-signatures-with-cisco-mars.html' title='Custom IPS Signatures with Cisco MARS Demo'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R81-ZsOcUkI/AAAAAAAAA3s/jIdiHAlkYVI/s72-c/ips_custom_icon.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-146598074761119540</id><published>2008-03-03T15:30:00.009Z</published><updated>2008-03-03T16:11:53.349Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco ASA VPN Usage with MARS'/><title type='text'>SSL VPN Event Reporting</title><summary type='text'>A customer asked me the other day "I`ve no access to the firewall, and Person X claims they are working at home today. Can i check with MARS if they`ve actually used the VPN."Not exactly, a major security event i know, but that data is in MARS. A quick look at the known WEBVPN events for the Cisco ASA, shows over 66, that MARS understands.So i basically set up a RAW event query on the ASA device,</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/146598074761119540/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=146598074761119540' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/146598074761119540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/146598074761119540'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/03/ssl-vpn-event-reporting.html' title='SSL VPN Event Reporting'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R8weHIvc9RI/AAAAAAAAA2k/YXxNzMHuhPE/s72-c/vpn_usage_graph.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1040982627395885797</id><published>2008-02-21T10:25:00.017Z</published><updated>2008-02-21T11:41:00.790Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tipping Point and Cisco MARS'/><title type='text'>Tipping Point with MARS</title><summary type='text'>Ok, MARS supports a number of different IDS/IPS vendors, out the box, including Netscreen, Symantec, ISS, Snort,Dragon and McAfee and obviously the Cisco IPS Range.Now if you were a member of the MARS User Group, you would know, its no secret, but you can also get Tipping Point IPS Sensors to work with MARS also.And here is the trick, Tipping Points Security Management System (SMS), can send </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1040982627395885797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1040982627395885797' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1040982627395885797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1040982627395885797'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/02/tipping-point-with-mars.html' title='Tipping Point with MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R71jIPSDCEI/AAAAAAAAA2Y/LP8rKnwks_U/s72-c/tipping_point.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7584814527353148728</id><published>2008-02-21T09:25:00.002Z</published><updated>2008-02-21T09:37:01.795Z</updated><title type='text'>Network World’s 20 Useful Sites for Cisco Networking Professionals</title><summary type='text'>This morning I was honoured to find out, that i am featured in Network World`s 20 useful sites for Cisco networking professionals.Quote "If you're studying for Cisco exams and just about to tear your hair out, don't fret, there are many others in the same position, and many of them are writing up their experiences in their blogs and passing along hints and tips. Even if you're a CCIE pro, there's</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7584814527353148728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7584814527353148728' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7584814527353148728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7584814527353148728'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/02/network-worlds-20-useful-sites-for.html' title='Network World’s 20 Useful Sites for Cisco Networking Professionals'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R71FSPSDB1I/AAAAAAAAA0g/jHgqbx-7ELc/s72-c/cisco_subnet.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3753353151137774801</id><published>2008-02-11T16:28:00.000Z</published><updated>2008-02-11T16:31:13.989Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS FSCK'/><title type='text'>Upgrade Note</title><summary type='text'>This is taken straight out of the release notes, and its definately something you should be aware of, at upgrade time....."The MARS Appliance performs a file system consistency check (fsck) on all disks when either of the following conditions is met:•If the system has not been rebooted during the past 180 days.•If the system has been rebooted 30 times.The fsck operation takes a long time to </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3753353151137774801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3753353151137774801' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3753353151137774801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3753353151137774801'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/02/upgrade-note.html' title='Upgrade Note'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4388270838541629131</id><published>2008-02-08T10:04:00.001Z</published><updated>2008-02-08T10:22:54.971Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.3.3'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 5.3.3'/><title type='text'>4.3.3 and 5.3.3 Released</title><summary type='text'>Cisco have released Cisco MARS 4.3.3 for Gen1 appliances, and 5.3.3 code for Gen2 appliances.The release notes can be found here - 4.3.3 and 5.3.3I`m not sure why theres such a difference in the file sizes, seeing as the only difference is updated Wireless LAN Controller support in the 5.3.3 code.For both releases, enhanced device support is as follows...Enhanced Cisco Device Support:   –FWSM </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4388270838541629131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4388270838541629131' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4388270838541629131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4388270838541629131'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/02/433-and-533-released.html' title='4.3.3 and 5.3.3 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R6wpUhTNMOI/AAAAAAAAA0I/ryHAPI1wquw/s72-c/updates.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8941811152686968460</id><published>2008-02-04T11:30:00.001Z</published><updated>2008-02-04T11:42:04.093Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Tips'/><title type='text'>Show Inventory</title><summary type='text'>Here a little tip, if you are using Gen 2 box, on a 5.x code.You need to get the serial number, for a license/TAC case etc, and its stuck in the rack, 3000 miles away.....There are 2 ways to get this, from the GUI, and from the CLI.From the CLI - If you SSH into the MARS box, and run a SHOW INVENTORY, you get the model number, whether its a local or global controller,  plus the Serial Number.[</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8941811152686968460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8941811152686968460' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8941811152686968460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8941811152686968460'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/02/show-inventory.html' title='Show Inventory'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/R6b5xhTNMNI/AAAAAAAAA0A/7MepjKy4WGc/s72-c/mars_serial.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1415114879039748</id><published>2008-01-18T11:51:00.000Z</published><updated>2008-01-18T12:14:44.104Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco IPS with MARS Part 3'/><title type='text'>Gen1 and 2 - Cisco IPS Part 3</title><summary type='text'>Okay Dokey, how do you add more than one Custom Signature at a time?This again is not documented, so i`ve experimented with a test box i have, and basically copied the format that the dynamic IPS updates use.Consider the example below, 2 Custom Sigs are in the XML file, one in RED and one in BLUE, with the remaining XML headers in bold.And this works fine..TroubleshootingNow an important note to </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1415114879039748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1415114879039748' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1415114879039748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1415114879039748'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/01/gen1-and-2-cisco-ips-part-3.html' title='Gen1 and 2 - Cisco IPS Part 3'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/R5CTaaC4uCI/AAAAAAAAAy4/JZzyXlnOqdw/s72-c/more_than_1.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3156030754077909700</id><published>2008-01-16T10:42:00.000Z</published><updated>2008-01-18T11:51:13.973Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Custom Signatures'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco IPS with MARS'/><title type='text'>Gen1 and 2 - Cisco IPS Part 2</title><summary type='text'>Following on from yesterdays article, i`m going to move onto adding Cisco IPS Custom Signatures into MARS.As you will probably already know, if you create a Custom IPS Sig, and this Signature is fired, with an alert to MARS, this will appear as an "Unknown Device Event Type"Why is this? Well simply put, MARS does not understand this Event, as its not defined in the MARS database, unlike all the </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3156030754077909700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3156030754077909700' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3156030754077909700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3156030754077909700'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/01/gen1-and-2-cisco-ips-part-2.html' title='Gen1 and 2 - Cisco IPS Part 2'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R43fp6C4t3I/AAAAAAAAAxg/DZaoMj7e3jo/s72-c/unknown_event_type.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2142576481938219665</id><published>2008-01-15T14:42:00.000Z</published><updated>2008-01-15T17:03:22.921Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco IPS with MARS'/><title type='text'>Gen2: Cisco IPS Features - Part 1</title><summary type='text'>One of the things i`m always asked is , what are the differences between then Gen1 and Gen2 appliances, as well as hardware changes?Well one difference, is the way that the MARS Box can integrate with Cisco IPS.If you are a Cisco IPS user, you will know, that you can Log IP packets associated with a Signature thats fired.You can view the trigger packets and IP log data associated with incidents </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2142576481938219665/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2142576481938219665' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2142576481938219665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2142576481938219665'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/01/gen2-cisco-ips-features-part-1.html' title='Gen2: Cisco IPS Features - Part 1'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R4zgZKC4tvI/AAAAAAAAAwk/As1OI1ysp5s/s72-c/rule.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7208375014621755208</id><published>2008-01-10T09:40:00.000Z</published><updated>2008-01-10T09:59:12.977Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAN Reading Room Paper'/><title type='text'>SANS Reading Room Paper</title><summary type='text'>I came across this paper below the other day, that`s worth a read to MARS newbies, in the SANS reading room.Entitled "Configuring and Tuning Cisco CS-MARS", this paper was produced by John Jarocki, for his GCIA Qualification.The paper is based on an older version of MARS, so note there have been some improvements like Dynamic IPS Updates since its creation.On another note, if you have something </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7208375014621755208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7208375014621755208' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7208375014621755208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7208375014621755208'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/01/sans-reading-room-paper.html' title='SANS Reading Room Paper'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R4XqU6C4ttI/AAAAAAAAAwU/Tg-fLMjH9hk/s72-c/sans_rr.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4918646893157479369</id><published>2008-01-06T20:29:00.000Z</published><updated>2008-01-06T21:12:21.200Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='MARS Models EOL'/><title type='text'>End-of-Sale and End-of-Life</title><summary type='text'>Happy new year to you all.Some news that appeared mid Dec 07, if you have not seen this already..Cisco have announced the end-of-sale and end-of life dates for the Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS) models 100, 100e, 200, GCm, and GC.Full info available here.Ok following the trend of other blogs, my prediction for 2008! I predict Cisco MARS will get </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4918646893157479369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4918646893157479369' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4918646893157479369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4918646893157479369'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2008/01/end-of-sale-and-end-of-life.html' title='End-of-Sale and End-of-Life'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-233640908529424951</id><published>2007-12-12T22:17:00.000Z</published><updated>2007-12-12T22:26:43.845Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.3.2 / 5.3.2'/><title type='text'>4.3.2 / 5.3.2 Release</title><summary type='text'>As promised links to the release notes for MARS 4.3.2 for Gen1 and 5.3.2 for Gen2 appliances.Release Notes for Cisco Security MARS Appliance 4.3.2Release Notes for Cisco Security MARS Appliance 5.3.2 As mentioned the other day, the major difference between the 2 release codes, is Wireless Controller support in 5.3.2, but not 4.3.2."Cisco Secure MARS 5.3. x supports the collection, parsing, and </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/233640908529424951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=233640908529424951' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/233640908529424951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/233640908529424951'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/12/432-532-release.html' title='4.3.2 / 5.3.2 Release'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/R2Be10wiKfI/AAAAAAAAAwM/oVsrp9dM12I/s72-c/new_sigs.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7791413591008146541</id><published>2007-12-12T12:46:00.000Z</published><updated>2007-12-12T12:48:05.079Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS 4.3.2'/><title type='text'>MARS 4.3.2 and 5.3.2 Released</title><summary type='text'>CS-MARS Versions 4.3.2 and 5.3.2 have been released.More info on these, when the release notes are posted!</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7791413591008146541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7791413591008146541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7791413591008146541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7791413591008146541'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/12/mars-432-and-532-released.html' title='MARS 4.3.2 and 5.3.2 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R1_YZkwiKeI/AAAAAAAAAwE/Zf0doKf5GnY/s72-c/4_3_2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4860766563517829150</id><published>2007-12-10T15:15:00.001Z</published><updated>2007-12-10T15:25:07.571Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS 5.3.2 Wireless Support'/><title type='text'>CS-MARS 5.3.2 Support for Wireless Controllers</title><summary type='text'>The ASK the expert forum has now finished, but you can still go over to the ASK the Expert Forums and read the posts.One that caught my eye, was the question "will there be a native support for Cisco access-points in further releases? "And Gary Halleen`s reponse, "Cisco access points will be supported through integration with the wireless controllers. This support comes in the 5.3.2 release, </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4860766563517829150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4860766563517829150' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4860766563517829150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4860766563517829150'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/12/cs-mars-532-support-for-wireless.html' title='CS-MARS 5.3.2 Support for Wireless Controllers'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R11YKEwiKdI/AAAAAAAAAv8/hl-AFK2GBfo/s72-c/wireless_support.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6836427111753384967</id><published>2007-11-29T11:13:00.000Z</published><updated>2007-11-29T11:19:50.229Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS Ask the Expert'/><title type='text'>New MARS Ask the Expert Discussion</title><summary type='text'>There is a new Net Pro, ask the Expert discussion, regarding the new features is MARS 4.3.1This is with Gary Halleen one of the authors of, the latest Cisco MARS Book.You can find this HERE.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6836427111753384967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6836427111753384967' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6836427111753384967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6836427111753384967'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/11/new-mars-ask-expert-discussion.html' title='New MARS Ask the Expert Discussion'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/R06fN5fSaBI/AAAAAAAAAv0/fuiDun_t0L0/s72-c/new_netpro_mars.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4842430994649980135</id><published>2007-11-21T10:06:00.000Z</published><updated>2007-11-21T10:21:15.550Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='EIQNetworks'/><category scheme='http://www.blogger.com/atom/ns#' term='MARS Archive'/><category scheme='http://www.blogger.com/atom/ns#' term='SecureVue'/><title type='text'>Extending CS-MARS Forensics and Reporting</title><summary type='text'>You may of heard of products that can make use of the Cisco MARS Archive data. There are 3 i`ve heard of that can do this, once such product is SecureVue from EIQNetworks.eIQ SecureVue provides extended forensics and investigative search capabilities that allow Cisco Security MARS customers to quickly search volumes of archived log data collected across the enterprise.SecureVue processes Cisco </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4842430994649980135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4842430994649980135' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4842430994649980135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4842430994649980135'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/11/extending-cs-mars-forensics-and.html' title='Extending CS-MARS Forensics and Reporting'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/R0QGWpfSaAI/AAAAAAAAAvs/mE6Qvkh7Bb4/s72-c/eiq_integration.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7227741757264709633</id><published>2007-11-14T09:06:00.000Z</published><updated>2007-11-14T09:10:47.746Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Netflow Performance Analysis'/><title type='text'>Netflow Performance Analysis</title><summary type='text'>Thanks to Joe Harris` 6200 Networks Blog, for a great link to Netflow Performance Analysis."Although many Cisco customers want to deploy NetFlow services, they are naturally cautious about introducing new technology into their network without completely understanding the potential performance impact. This paper examines the CPU impact of enabling NetFlow services in various scenarios on several </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7227741757264709633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7227741757264709633' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7227741757264709633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7227741757264709633'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/11/netflow-performance-analysis.html' title='Netflow Performance Analysis'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7883083332180643379</id><published>2007-11-07T10:19:00.000Z</published><updated>2007-11-07T11:34:15.151Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS IPS 6 Dynamic Updates'/><title type='text'>MARS Cisco IPS 6 Dynamic Updates</title><summary type='text'>Beginning in 4.3.1 and 5.3.1, MARS can discover new Cisco IPS signatures and correctly process and categorize received events that match those signatures.Note, the Dynamic IPS Update feature is not enabled by default, and has to be configured as pictured above. Now there are two ways to get the updates. One is automatically (via a schedule) from Cisco, where a valid username and password is </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7883083332180643379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7883083332180643379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7883083332180643379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7883083332180643379'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/11/mars-cisco-ips-6-dynamic-updates.html' title='MARS Cisco IPS 6 Dynamic Updates'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/RzGacXjbZrI/AAAAAAAAAts/5ghHVJ5bnB4/s72-c/ips_update_settings.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-3627038653071639892</id><published>2007-11-02T17:29:00.001Z</published><updated>2007-11-02T21:40:05.701Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Book Review LAN Switch Security'/><title type='text'>Book Review: LAN Switch Security</title><summary type='text'>Title: LAN Switch Security: What Hackers Know About Your SwitchesAuthors: Eric Vyncke and Christopher PaggenPublisher: Cisco PressQuote "Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/3627038653071639892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=3627038653071639892' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3627038653071639892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/3627038653071639892'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/11/book-review-lan-switch-security.html' title='Book Review: LAN Switch Security'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/RyuWtnjbZqI/AAAAAAAAAtk/tbnEKEZCXpM/s72-c/what_hackers.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1944129796872047099</id><published>2007-10-25T15:32:00.000Z</published><updated>2007-10-25T16:21:21.999Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS Unlock'/><title type='text'>Unlocking User Accounts via the CLI</title><summary type='text'>As promised, a short article on unlocking user accounts via the CLI.MARS 4.3.1 introduced the new AAA features.For both Local or AAA authentication methods, if enabled, GUI access is locked for an account upon login failure, which occurs when a specified number of incorrect password entries are made for a single login name.Now an important thing to note. The administrator GUI access can be locked</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1944129796872047099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1944129796872047099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1944129796872047099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1944129796872047099'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/10/unlocking-user-accounts-via-cli.html' title='Unlocking User Accounts via the CLI'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_ohceiKUYGG8/RyC_v3jbZjI/AAAAAAAAAss/Yj9B_IGIZ8A/s72-c/unlock_all.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-2723026638528701236</id><published>2007-10-09T14:33:00.000Z</published><updated>2007-10-09T16:35:25.104Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS AAA with Microsoft IAS Server'/><title type='text'>MARS AAA with Microsoft IAS</title><summary type='text'>I was going to do a write up on configuring the new MARS 4.3.1 AAA authentication feature with Cisco ACS.But to be honest, there is a great write up in the official MARS documentation on doing just that, so in this article i`ll show you how to configure AAA with Microsoft IAS Server, for those of you who dont own an ACS Box.We'll use Microsoft IAS, and if you dont know, this is the Microsoft </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/2723026638528701236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=2723026638528701236' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2723026638528701236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/2723026638528701236'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/10/mars-aaa-with-microsoft-ias.html' title='MARS AAA with Microsoft IAS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/RwuTPLeJC_I/AAAAAAAAAo0/gIIEVXmtc60/s72-c/IAS.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4408536431045956717</id><published>2007-10-02T08:43:00.000Z</published><updated>2007-10-02T21:20:29.604Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='642-544'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS Exam'/><title type='text'>642-544 cisco MARS Exam</title><summary type='text'>I get a lot of visitors to the Blog via the keyword 642-544, so I thought i`d give the new MARS exam another mention.The MARS exam is part of the Cisco CCSP Certification Track, and there are a couple of training courses available in the official Instructor Led Course or 3rd Party Hands On Real World Training Course by Priveon.There are also two books available, Security Threat Mitigation and </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4408536431045956717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4408536431045956717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4408536431045956717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4408536431045956717'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/10/642-544-cisco-mars-exam.html' title='642-544 cisco MARS Exam'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/RwIFBbeJC2I/AAAAAAAAAns/69COB2fMC40/s72-c/mars_exam.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7550227418863624538</id><published>2007-10-01T10:10:00.001Z</published><updated>2007-10-01T10:20:03.325Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='IronPort Seminar'/><title type='text'>UK Email and Web Security Seminars</title><summary type='text'>For readers in the UK, there are still some limited spaces available, this week and next, at a Cisco/Ironport Email and Web Security event."Satisnet in conjunction with Cisco invite you to a seminar aimed at educating you on the Ironport solutions and how they can save you time and money in terms of managing your messaging and web environment and enabling sophisticated secure business messaging </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7550227418863624538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7550227418863624538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7550227418863624538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7550227418863624538'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/10/uk-email-and-web-security-seminars.html' title='UK Email and Web Security Seminars'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/RwDHtreJC1I/AAAAAAAAAnk/9-JGaWceSgk/s72-c/ironport.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-1630851848503963606</id><published>2007-09-27T10:08:00.000Z</published><updated>2007-09-27T10:18:49.521Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS 4.3.1'/><title type='text'>Cisco MARS 4.3.1 Now Available</title><summary type='text'>Cisco MARS 4.3.1 is now available (and 5.3.1 for Gen2).There are some great new features, briefly mentioned below...Data Migration Support   Beginning with this release, you can migrate configuration and event data from a MARS Appliance running 4.x to a newer model running 5.x.Centralized Password Management—External AAA Server Support   External Authentication, Authorization, and Auditing (AAA) </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/1630851848503963606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=1630851848503963606' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1630851848503963606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/1630851848503963606'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/09/cisco-mars-431-now-available.html' title='Cisco MARS 4.3.1 Now Available'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_ohceiKUYGG8/RvuCfLeJC0I/AAAAAAAAAnc/axyoEgLGLa0/s72-c/4_3_1_sigs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-7208431527364687020</id><published>2007-09-26T08:16:00.000Z</published><updated>2007-09-26T09:08:40.196Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Guard and Detector Custom Parser'/><title type='text'>Guard &amp; Detector Custom Parser</title><summary type='text'>As promised an example Custom Parser for the impressive Cisco Guard &amp; Detector.Like any Cisco device, these appliances or Catalyst 6500 Modules can produce syslog. And since these devices are not on the MARS supported Device list, a Custom Parser was needed for MARS to understand the incoming syslog, to convert to Events.I created a few Log Parser Templates for a section of Guard Events, </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/7208431527364687020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=7208431527364687020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7208431527364687020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/7208431527364687020'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/09/guard-detector-custom-parser.html' title='Guard &amp; Detector Custom Parser'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_ohceiKUYGG8/RvoWS7eJCrI/AAAAAAAAAmU/A2HKiek4qMk/s72-c/New+Picture+%282%29.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8791868342766902830</id><published>2007-09-24T16:36:00.000Z</published><updated>2007-09-24T16:43:16.725Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='CS-MARS Guard and Detector'/><title type='text'>Cisco Guard and Detector</title><summary type='text'>Appologies for the lack of updates, i`ve been working away on a DDOS project utilizing the Cisco Guard and Detector.These appliances (or Cat 6500 Modules) are based upon the patented Multi-Verification Process (MVP) architecture.This MVP architecture enables the Cisco Guard and Cisco Traffic Anomaly Detector to leverage the latest analysis and attack recognition techniques to detect and remove </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8791868342766902830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8791868342766902830' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8791868342766902830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8791868342766902830'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/09/cisco-guard-and-detector.html' title='Cisco Guard and Detector'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_ohceiKUYGG8/Rvfn4reJCmI/AAAAAAAAAls/l_qmYKM6teA/s72-c/DDOS_Graph.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4168367846344492588</id><published>2007-09-02T20:58:00.000Z</published><updated>2007-09-02T21:10:03.807Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco MARS 4.2.8'/><title type='text'>MARS 4.2.8 Released</title><summary type='text'>Sorry for no new posts over the last 2 weeks, (and appologies if you have emailed, and had no reply)  i`ve been on Hols to Greece and Turkey.Old news now, but MARS 4.2.8 was released whilst I was away.Release notes for Cisco Security MARS Appliance 4.2.8 are available Here.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4168367846344492588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4168367846344492588' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4168367846344492588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4168367846344492588'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/09/mars-428-released.html' title='MARS 4.2.8 Released'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/RtslgLoIquI/AAAAAAAAAkk/-Ppxw-a3Pnk/s72-c/4_2_8_sigs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-4091035959743362062</id><published>2007-08-16T16:02:00.000Z</published><updated>2007-08-16T16:59:35.607Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trend Micro DCS integration with MARS'/><title type='text'>New Trend Micro DCS MARS Integration</title><summary type='text'>Trend Micro have come up with a new Integration for Cisco MARS, utilising there own Damage Cleanup Services.Quote"Trend Micro Damage Cleanup Service extends the capability of MARS not just to notify administrators of worm and spyware incidents but to also perform remediation action automatically within seconds after the incident has been identified by MARS. After DCS server completed its </summary><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=ce4699b26afe1bb5&amp;type=video%2Fmp4' length='0'/><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/4091035959743362062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=4091035959743362062' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4091035959743362062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/4091035959743362062'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/08/new-trend-micro-dcs-mars-integration.html' title='New Trend Micro DCS MARS Integration'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/RsR1VboIqqI/AAAAAAAAAkE/Z9FnjF9PTnc/s72-c/DCS_Title.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-8233588221901455218</id><published>2007-08-07T15:39:00.000Z</published><updated>2007-08-07T15:48:42.984Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco NAC Appliance Custom Parser'/><title type='text'>NAC Appliance Custom Parser</title><summary type='text'>The NAC Appliance Custom Parser has been available in the User Group for a while now. I`ve finally found the time to set this up for myself (and not a customer!) in the test lab, so i can produce a demo.Its really simple to setup, but give yourself a couple of hours, as there are over 60 templates to define.Once done, MARS can then understand the raw event messages coming in from the Clean Access</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/8233588221901455218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=8233588221901455218' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8233588221901455218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/8233588221901455218'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/08/nac-appliance-custom-parser.html' title='NAC Appliance Custom Parser'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_ohceiKUYGG8/RriS2vxMFOI/AAAAAAAAAjM/PrNMekBhHZs/s72-c/nac_custom_parser.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6675753028306608479</id><published>2007-08-05T20:41:00.000Z</published><updated>2007-08-05T21:23:58.274Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Security MARS'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco Book Review'/><title type='text'>Book Review: Cisco Security MARS</title><summary type='text'>Title: Security Monitoring with Cisco Security MARSAuthors: Gary Halleen and Greg KelloggPublisher: Cisco PressQuote"Security Monitoring with Cisco Security MARS helps you plan a MARS deployment and learn the installation and administration tasks you can expect to face."Top marks from me, for this book, and not just because i try to beg/borrow content for the Blog from the Authors!You may think </summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6675753028306608479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6675753028306608479' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6675753028306608479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6675753028306608479'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/08/book-review-cisco-security-mars.html' title='Book Review: Cisco Security MARS'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ohceiKUYGG8/RrY3N_xMFMI/AAAAAAAAAi8/Y_nFKi0_-4A/s72-c/new_mars_book.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6783261041994986809</id><published>2007-08-02T21:36:00.000Z</published><updated>2007-08-02T21:38:48.752Z</updated><title type='text'>MARS Exam delayed</title><summary type='text'>Good job I didnt wait for the MARS exam for my recertification.This has been put back to the 15th August 2007.</summary><link rel='replies' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/6783261041994986809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34995790&amp;postID=6783261041994986809' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6783261041994986809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/posts/default/6783261041994986809'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2007/08/mars-exam-delayed.html' title='MARS Exam delayed'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://photos1.blogger.com/blogger/1832/3885/1600/blackhat.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ohceiKUYGG8/RrJOdfxMFLI/AAAAAAAAAi0/iRVrbuazzoU/s72-c/mars_exam.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
