Install and Setup Guide for Cisco Security MARS Release 5.3.X March 2008
Total Page:16
File Type:pdf, Size:1020Kb
Install and Setup Guide for Cisco Security MARS Release 5.3.x March 2008 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Customer Order Number: Text Part Number: OL-14672-01 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. CCVP, the Cisco logo, and Welcome to the Human Network are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn is a service mark of Cisco Systems, Inc.; and Access Registrar, Aironet, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, iQuick Study, LightStream, Linksys, MeetingPlace, MGX, Networkers, Networking Academy, Network Registrar, PIX, ProConnect, ScriptShare, SMARTnet, StackWise, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries. All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0711R) Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental. Install and Setup Guide for Cisco Security MARS Copyright © 2007 Cisco Systems, Inc. All rights reserved. CONTENTS Preface xi Audience ii-xi Organization ii-xi Conventions ii-xii Warning Definition ii-xiii Related Documentation ii-xvii Obtaining Documentation, Obtaining Support, and Security Guidelines ii-xvii CHAPTER 1 Appliance Overview and Specifications 1-1 System Description 1-1 Local Controller 1-2 Global Controller 1-3 MARS Web Interface 1-3 Reporting and Mitigation Devices 1-3 Network Cable Requirements 1-4 Hardware Descriptions—MARS 25R, 25, 55, 110R, 110, 210, GC2R, and GC2 1-4 Technical Specifications for MARS 25R, 25, and 55 1-5 Technical Specifications for MARS 110R, 110, 210, GC2, and GC2R 1-7 Part Numbers, License Key, and Serial Numbers 1-8 Serial Numbers 1-9 License Key 1-9 Removing and Replacing the Front Bezel 1-9 MARS 25R and 25 Front and Back Panels 1-11 Front Panel Features—MARS 25 and 25R 1-11 Control Panel Description—MARS 25R and 25 1-11 Control Panel LED Descriptions—MARS 25R and 25 1-12 Back Panel Features—MARS 25R and 25 1-12 MARS 55 Front and Back Panels 1-13 Front Panel Features—MARS 55 1-13 Control Panel Description—MARS 55 1-14 Control Panel LED Descriptions—MARS 55 1-14 Back Panel Features—MARS 55 1-15 Hard Drive Slot Number Layout—MARS 55 1-16 Power Supply Description—MARS 25R, 25, and 55 1-16 Install and Setup Guide for Cisco Security MARS OL-14672-01 iii Contents AC Power Source Requirements 1-17 MARS 110R, 110, 210, GC2R, and GC2 Front and Back Panels 1-17 Front Panel Features—MARS 110R, 110, 210, GC2R, and GC2 1-17 Control Panel Description—MARS 110R, 110, 210, GC2R, and GC2 1-18 Control Panel LED Descriptions—MARS 110R, 110, 210, GC2R, and GC2 1-20 Back Panel Features—MARS 110R, 110, 210, GC2R, and GC2 1-22 Connector Descriptions 1-23 Hard Drive Layout 1-26 Redundant Power Supply Descriptions 1-26 AC Power Source Requirements 1-28 Power Supply LED Descriptions 1-28 Checking Power Supply Operational Status 1-29 1-29 CHAPTER 2 Deployment Planning Guidelines 2-1 MARS Components 2-1 Supporting Devices 2-1 Required Traffic Flows 2-2 CHAPTER 3 Preparing for Installation 3-1 Safety 3-1 Warnings and Cautions 3-1 General Precautions 3-3 Maintaining Safety with Electricity 3-4 Protecting Against Electrostatic Discharge 3-4 Preventing EMI 3-5 Preparing Your Site for Installation 3-5 Environmental 3-5 Choosing a Site for Installation 3-6 Grounding the System 3-7 Creating a Safe Environment 3-7 AC Power 3-7 Cabling 3-7 Inline Filter for the Modem 3-7 Precautions for Rack-Mounting 3-8 Precautions for Products with Modems, Telecommunications, or Local Area Network Options 3-8 Required Tools and Equipment 3-9 Packaging Contents Checklist 3-9 Install and Setup Guide for Cisco Security MARS iv OL-14672-01 Contents Selecting the Appropriate Rail Kit 3-10 Web Browser Client Requirements 3-10 Configuring Internet Explorer Settings 3-10 Configuring Pop-Up Blockers 3-14 Correcting Issues Caused by the 832894 (MS04-004) Security Update or the 821814 Hotfix 3-15 Obtaining the Required Browser Plug-ins 3-15 Web Browser Client Usage Guidelines and Notes 3-16 CHAPTER 4 Installing the Appliance 4-1 Installation Quick Reference 4-1 Installing the MARS Appliance in a Rack 4-2 Rack-Mounting MARS Appliances 110R, 110, 210, GC2R, and GC2 4-4 Installing the Chassis Handles 4-4 Basic Rail Rack-Mount Installation 4-5 Basic Rail Rack-Mount Removal 4-5 Fixed Bracket Rack-Mount Installation 4-5 Fixed Bracket Rack Mount Removal 4-7 Tool-less Rail Rack-Mount Servicing 4-7 Connecting to the AC Power Source 4-7 Connecting Cables 4-8 Powering on the Appliance and Verifying Hardware Operation 4-8 CHAPTER 5 Initial MARS Appliance Configuration 5-1 Checklist for Initial Configuration 5-1 Establishing a Console Connection 5-4 Configuring Basic Network Settings at the Command Line 5-6 Change the Default Password of the System Administrative Account 5-6 Specify the IP address and Default Gateway for the Eth0 Interface 5-7 Specify the IP Address and Default Gateway for the Eth1 Interface 5-8 Specify the Appliance Hostname 5-9 Set Up Additional Routes 5-9 Add a Static Route 5-10 Delete a Static Route 5-10 Specify the Time Settings 5-10 Completing the Cable Connections 5-11 Completing the Configuration using MARS web interface 5-11 Licensing the Appliance 5-11 License the 5.x Software 5-11 Install and Setup Guide for Cisco Security MARS OL-14672-01 v Contents Verifying and Updating Network Settings 5-14 Specifying the DNS Settings 5-15 Configure E-mail Settings for the System Administrative Account 5-16 Configure TACACS/AAA Login Prompts 5-17 Updating the Appliance to the Most Recent Software 5-18 Next Steps 5-18 CHAPTER 6 Administering the MARS Appliance 6-1 Performing Command Line Administration Tasks 6-1 Log In to the Appliance via the Console 6-2 Reset the Appliance Administrator Password 6-2 Shut Down the Appliance via the Console 6-3 Log Off the Appliance via the Console 6-3 Reboot the Appliance via the Console 6-4 Determine the Status of Appliance Services via the Console 6-4 Stop Appliance Services via the Console 6-5 Start Appliance Services via the Console 6-5 View System Logs via the Console 6-6 Checklist for Upgrading the Appliance Software 6-6 Burn an Upgrade CD-ROM 6-10 Prepare the Internal Upgrade Server 6-10 Important Upgrade Notes 6-11 General Notes 6-11 Upgrade to 5.3.2 6-11 Upgrade to 5.3.1 6-11 Upgrade to 5.2.8 6-12 Upgrade to 5.2.7 6-12 Determine the Required Upgrade Path 6-12 Download the Upgrade Package from Cisco.com 6-12 Specify the Proxy Settings for the Global Controller or Local Controller 6-13 Upgrade Global Controller or Local Controller from its User Interface 6-14 Upgrade from the CLI 6-15 Upgrading a Local Controller from the Global Controller 6-17 Specify the Proxy Settings in the Global Controller 6-18 Upgrade Local Controller from the Global Controller User Interface 6-18 Configuring and Performing Appliance Data Backups 6-19 Typical Uses of the Archived Data 6-21 Format of the Archive Share Files 6-21 Archive Intervals By Data Type 6-23 Install and Setup Guide for Cisco Security MARS vi OL-14672-01 Contents Configure