PRODUCT OVERVIEW
• Cisco® Network Intrusion Prevention Systems (IPS)
• Cisco® Network Intrusion Detection Systems (IPS)
• Cisco Switch IDS
• Cisco IOS® routers with inline Intrusion Prevention System (IPS) functions
• Cisco IDS modules for routers
• Cisco PIX® firewalls
• Cisco Catalyst® 6500 Series Firewall Services Modules (FWSM)
• CiscoWorks Management Center for Cisco Security Agents
• CiscoWorks Monitoring Center for Security servers
• Monitor attacks against specific, high-visibility hosts (for example, a Web server)
• Monitor the traffic for patterns of attacks
• Correlate IPS information from multiple security devices (for example, firewall, network IDS, host IDS)
• Receive early notification of emerging threats
• Trigger an automated response, as a corrective action against an attack
• Schedule or produce reports on demand
• VPNs
• Firewalls
• Network IPSs
• Network IDSs
• Host-based IPSs
• Router-based IPSs
New Features
• A Security Device Event Exchange (SDEE) server that can be used for hierarchical event monitoring
• Support for Cisco IOS routers with inline intrusion prevention software
• Support for IPS 5.0, which allows the operator to monitor network IPS sensors that communicate using the Security Device Event Exchange (SDEE), allowing the operator to subscribe to specific IPS event types and better control which events are received
• New Action Types for IPS to include: Deny Attacker, Deny Flow, and Deny Packet
• New Risk Rating for IPS-The risk scaling algorithm is at the heart of increasing the confidence level of the analysis and allows the user to control the "paranoia" level at which they choose to take actions
• Filter Options-The ability to filter on: Severity, Locality, Signature Family, Signature Name, Source/Destination Port, Risk Rating, Alarm Trait, and Sensor Name
• Copy and Past form Event Viewer
• Enhancements in the event viewer include performance improvements for event deletions and an addition of a new interface graphing capability
• Icon bar and console notifications for completion of reports, error situations, and system messaging
• Persistence of the preferred column ordering in the event viewer
• Flexible storage options for reports, including to the database or a file
• Additional reports for firewalls and Cisco security agents
• An increase in the number of active events rules, which help identify critical events and automate responses to them
• The ability to import Cisco IPS Sensor configurations from a remote Management Center for IPS Sensors server
FEATURES AND BENEFITS
Comprehensive Reporting Options for Finding Information
• Web-based wizard for creating flexible security reports
• Reporting template system offering personalized list of common reports
• On-demand and scheduled reports
• Reports by top incidents, by IP address, by time, by signature, by event, etc.
• Notifications of reports sent by e-mail
Web-Based Event Viewer with Features to Easily Locate Attacks
Perform Event Correlation to Detect an Emerging Threat
• Create user-defined rules for establishing relationships between events (correlate by type of event, by time, across sensors, across source addresses, etc.). This helps to identify attacks that may not be apparent from a single event.
• The user can define thresholds and time periods when a rule should be triggered.
• If a rule is triggered, the user can be notified by e-mail and fine-tune what information from the suspicious packet is forwarded with the e-mail. Alternatively, the user automatically can execute a script as a corrective response.
Database Management
Table 1. Supported Devices
|
Devices Supported for Monitoring |
Platforms Supported for Monitoring |
|
Cisco Network IPS Sensors
|
Software Version Supported: Cisco IDS Sensor Software versions 4.0, 4.1, and 5.0 (Subject to change-see http://www.cisco.com/go/vms for most up-to-date information.) |
|
Cisco Switch IDS (IDSM) Sensors
|
IDSM 4.0, 4.1, and 5.0 |
|
Cisco IPS Network Module for Cisco Routers
|
• Cisco IDS Sensor Software Version 4.1
• Cisco IPS Sensor Software Version 5.0
|
|
Cisco 1700, 2600, and 7200 Series Routers, Cisco 3725 and 3745 Multiservice Access Routers, and the Cisco 2691 Multiservice Platform
|
Cisco IOS Software Release 12.3(8)T4 and later with Inline Intrusion Prevention Software support |
|
Cisco PIX Firewall
|
Cisco PIX Firewall OS 6.0(x), 6.1(x), 6.2(x), and 6.3.1 |
|
Cisco Firewall Services Modules
|
Release 1.1 |
|
Cisco Security Agents (Forwarded by Management Center for Cisco Security Agents)
|
Release 4.5 |
SYSTEM REQUIREMENTS
ORDERING INFORMATION
SERVICE AND SUPPORT
FOR MORE INFORMATION
