navbar
Brochures

How to PDF acrobat

Table Of Contents

Overview

CiscoWorks VMS Functions

Firewall Management

Auto Update Server for Firewall Management

Network-Based IDS Management

Host-Based IPS Management

VPN Router Management

Security Monitoring

Monitoring for Performance

Performance Monitoring

Operational Management

Server Specifications (Minimum Requirements)

Server Hardware

Server Operating System

Java Requirements

Client Requirements

Hardware

Client Operating System

Client Browser

Service and Support

Ordering Information

Positioning with CiscoWorks VMS Basic

For More Information

Overview


CiscoWorks VPN/Security Management Solution
Version 2.2

CiscoWorks VPN/Security Management Solution (VMS) is the flagship integrated security management solution from Cisco Systems®. It protects productivity and reduces operating costs for enterprises by combining Web-based tools for configuring, monitoring, and troubleshooting enterprise VPNs, firewalls, network-based intrusion detection systems (IDSs), and host-based intrusion prevention systems (IPSs). CiscoWorks VMS is an integral part of the SAFE Blueprint from Cisco® for network security, and delivers the industry's first robust and scalable foundation and feature set that addresses the needs of small- and large-scale VPN and security deployments.

Today's business challenges and resulting security deployments require more than the ability to support numerous devices. Many customers have limited staffing, yet are asked to manage several different types of security devices. They must manage the security and network infrastructure; frequently update remote devices; implement change control and auditing, when multiple groups are involved in defining and deploying policies; enhance security without adding more headcount; and deploy remote-access VPNs to all employees and monitor the VPN service.

CiscoWorks VMS enables customers to deploy security infrastructures from small to large environments, using the following powerful features:

Integrated infrastructure management

CiscoWorks VMS uniquely manages SAFE Blueprint components, including firewalls, VPNs, network IDSs, and host IPSs. Effective management involves more than configuring devices—CiscoWorks VMS provides a complete range of configuration, monitoring, and troubleshooting features. CiscoWorks VMS manages not only the security infrastructure but also the network infrastructure. Customers benefit from being able to manage these components through one solution. CiscoWorks VMS delivers integrated monitoring of Cisco PIX® firewalls, Cisco IOS® Software, network-based IDSs, and host-based IPSs, along with event correlation.

Scalable foundation

CiscoWorks VMS implements a foundation that makes it easier to scale management to many devices. CiscoWorks VMS provides users with a consistent GUI to reduce learning time, workflow to allow multiple administrators to work together and coordinate tasks, access control server (ACS) integration to precisely control access, support for Windows and Solaris platforms, use of a robust database engine, simplified installation, and more. An industry-leading feature of this foundation is the Auto Update feature, which allows numerous devices to be updated easily and quickly. Auto Update enables devices, even remote and dynamically addressed devices, to periodically "call home" to an update server and pull the most current security configurations or Cisco PIX operating system. Auto Update is required to effectively scale remote-office firewall deployments across intermittent links or dynamic addresses. Prior policy updating methods relied on a "push" model. Although this model works for known devices, it does not work for remote devices with unknown addresses or devices that are not always active. Without Auto Update, a more manual process is required to update each remote device. The Auto Update feature provides a dramatic scalability improvement for organizations that want to deploy devices with many remote and local locations.

Consistent implementation of corporate security policy

CiscoWorks VMS enables organizations to easily implement corporate security policies across multiple locations. For example, the Smart Rules feature allows an administrator to define a device group for the New York sales office and deploy that same policy to all other sales offices quickly and consistently. In addition to easier and faster policy updates, Auto Update provides consistent policy deployment for remote devices. The Command and Control Workflow feature provides change control and auditing, and is particularly important for customers who have separate groups for network and security operations. The solution includes workflow processes for generating, approving, and deploying configurations. This can help organizations delegate tasks to different administrators while still functioning as a team. An audit of the changes can be maintained.

Centralized role-based access control (RBAC)

CiscoWorks VMS allows RBAC and enables groups to have different access rights across different devices and applications, providing precise and secure control.

CiscoWorks VMS Functions

CiscoWorks VMS is launched from the CiscoWorks dashboard and is organized into several functional areas:

Firewall management

Auto Update Server

Network IDS management

Host IPS management

VPN router management

Security monitoring

VPN monitoring

Operational management

Figure 1 shows CiscoWorks VMS displayed as a "drawer" in the CiscoWorks dashboard.

Firewall Management

CiscoWorks VMS enables the large-scale deployment of Cisco PIX firewalls by providing the following features:

Smart Rules hierarchy and inheritance

User-defined device and customer groups, including nesting

Global role-based access with administrative privileges per device and customer groups with other CiscoWorks products and Cisco Secure ACS

Mandatory and default device settings inheritance

Workflow deployment to device, directory, or Auto Update Server

Look and feel of Cisco PIX Device Manager but with scalability to thousands of Cisco PIX firewalls

Integration with other CiscoWorks network management software

Complete SAFE Blueprint coverage for centralized management of Cisco PIX firewalls, including access control, VPN, IDS, and authentication, authorization, and accounting (AAA)

The Smart Rules feature allows common information, including access rules and settings, to be inherited for all firewalls in a device or customer group. Smart Rules allows a user to define common rules once, which results in reduced configuration time, fewer administrative errors, and higher device scalability. Using Smart Rules, a user can configure a common rule (such as allowing all HTTP traffic) once and can apply this rule globally to all firewalls. Smart Rules can also be defined on a device or customer group basis. For specific information on CiscoWorks firewall management, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps3992/index.html.

Auto Update Server for Firewall Management

CiscoWorks VMS introduces the industry's first firewall Auto Update Server that allows users to implement a "pull" model for security and Cisco PIX operating system management. Auto Update Server permits remote firewall networks with unprecedented scalability. The Auto Update Server allows Cisco PIX firewalls to periodically and automatically contact the update server for any security configuration, Cisco PIX operating system, and Cisco PIX Device Manager updates. The Auto Update Server supports the following features:

Security management of remote Cisco PIX firewalls that use Dynamic Host Control Protocol (DHCP)

Automated Cisco PIX OS distribution to groups of Cisco PIX firewalls

Automated Cisco PIX Device Manager updates to remote firewalls

Configuration verification at periodic intervals

Automated replacement of inaccurate or tampered configurations

New firewalls configured at "boot time"

The Auto Update Server is an indispensable component of any large-scale remote Cisco PIX firewall deployment—an easy-to-use solution that automatically updates all remote or local firewalls with new operating system releases. Cisco is the industry's first vendor to provide this pull model of security policy and operating system management. For specific information on the Auto Update Server component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps3993/index.html

Network-Based IDS Management

Administrators can use CiscoWorks VMS to configure network and switch IDS sensors. Many sensors can be quickly configured using group profiles. Additionally, a more powerful signature management feature is included to increase the accuracy and specificity of detection. Some prominent features are:

Easy-to-use Web-based interface

Wizards that lead users through common management tasks

Access to the Network Security Database (NSDB), which provides meaningful information about alarms for users without IDS security expertise

Ability to define a hierarchy of sensors containing groups and subgroups, and the ability to configure multiple sensors concurrently using group profiles

Support for several hundred sensor deployments from each console

Use of a robust relational database to store a high volume of data

For specific information about the network-based IDS management component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps3990/index.html.

Host-Based IPS Management

CiscoWorks VMS provides threat protection for server and desktop computing systems, also known as "endpoints." CiscoWorks VMS goes beyond conventional endpoint security solutions by identifying and preventing malicious behavior before it can occur, thereby removing potential known and unknown security risks that threaten enterprise networks and applications. Because CiscoWorks VMS analyzes behavior rather than relying on signature matching, its solution provides robust protection with reduced operational costs. Features of host-based IPS management include:

Aggregates and extends multiple endpoint security functions by providing host intrusion prevention, distributed firewall, malicious mobile code protection, operating system integrity assurance, and audit log consolidation—all within a single agent

Provides preventive protection against entire classes of attacks, including port scans, buffer overflows, Trojan horses, malformed packets, and e-mail worms

Offers "zero update" prevention for known and unknown attacks

Provides industry-leading protection for UNIX and Windows servers and Windows desktops, allowing customers to patch systems on their own schedules

Open and extensible architecture offers the capability to define and enforce security according to corporate policy

Scalable to thousands of agents per manager to support large enterprise deployments

For specific information about the host-based IPS management component of CiscoWorks VMS, refer to the Management Center for Cisco Security Agents data sheet.
http://www.cisco.com/en/US/products/sw/cscowork/ps5212/index.html

VPN Router Management

CiscoWorks VMS includes functions for the setup and maintenance of large deployments of VPN connections and provides users with a point-and-click interface for setting up and deploying connections. This component is intended for scalable configuration of site-to-site VPN connections in a hub-and-spoke topology for centralized, multidevice configuration and deployment of Internet Key Exchange (IKE) and IP Security (IPSec) tunneling policies on VPN routers.

Major features include:

Wizard-based interface for the creation of IKE and VPN tunneling policies

Hierarchical inheritance and Smart Rules hierarchy to reflect the organizational and common setup of devices and simplified device management

IKE-KA (IKE Keepalive) or generic routing encapsulation (GRE) with Open Shortest Path First (OSPF) and Enhanced Interior Gateway Routing Protocol (EIGRP) for failover routing scenarios

Centralized RBAC model allows for centralized management of users and accounts

For specific information about the VPN router management component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps3994/index.html.

Security Monitoring

CiscoWorks VMS provides integrated monitoring to reduce the number of security monitoring consoles, reduce the number of events to monitor, and provide a broader view of security status.

Integrated monitoring is used to capture, store, view, correlate, and report on events from many of the devices in the SAFE Blueprint, such as Cisco network-based IDSs, switch-based IDSs, host-based IPSs, firewalls, and routers.

Event correlation is used to identify attacks that are not easily recognizable from a single event. A flexible notification scheme and automated responses to critical events also aid in quick action.

The event viewer can read both real-time and historical events.

Events are color-coded and administrators can quickly isolate problems. Administrators can also define thresholds and time periods when rules can be triggered to provide notification.

On-demand and scheduled reports facilitate ongoing monitoring.

For specific information about the security-monitoring component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps3991/index.html

Monitoring for Performance

CiscoWorks VMS introduces improved functions for monitoring and troubleshooting the performance of services that contribute to enterprise network security. The functions will enable the user to:

Monitor the status of VPNs

Correlate and graphically display metrics associated with active VPNs

Identify all networks and users connected by VPNs on a per-device basis

Monitor the real-time device statistics of firewalls

Monitor the performance of the Cisco Catalyst® Content Switching Module (CSM) and Cisco Catalyst Secure Sockets Layer (SSL) Module

For specific information about the performance monitoring component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps5387/index.html.

Performance Monitoring

The Monitoring Center for Performance component, within the CiscoWorks VPN/Security Management Solution (VMS), is a web-based tool for monitoring and troubleshooting the health and performance of services that contribute to enterprise network security. The Monitoring Center for Performance enables users, without requiring expertise with IPSEC or other security technologies, to increase service availability by isolating, troubleshooting significant events in their network as they occur.

The Monitoring Center for Performance can monitor and troubleshoot health and performance of:

Cisco VPN Concentrators

Cisco VPN Routers

Cisco PIX Firewalls

Cisco Catalyst Firewall Service Modules

Cisco Catalyst VPN Service Modules

Cisco Catalyst CSM Service Modules

Cisco Catalyst SSL Service Modules

Operational Management

CiscoWorks VMS provides the operational management for the network, allowing network managers to perform the following:

Quickly build a complete network inventory

Manage device credentials information

Monitor and report on hardware, software, configuration, and inventory changes

Manage and deploy configuration changes and software image updates to multiple devices

Monitor and troubleshoot critical LAN and WAN resources

Quickly identify devices that can be used for VPNs, if upgraded with the appropriate Cisco IOS Software

Discover which VPN devices have hardware encryption modules

Graphically compare configurations of VPN devices

Isolate IPSec-related problems by running customized syslog reports

For specific information on the operational management component of CiscoWorks VMS, refer to:
http://www.cisco.com/en/US/products/sw/cscowork/ps2073/index.html.

Server Specifications (Minimum Requirements)

Server Hardware

CiscoWorks VMS requires one of the following servers:

PC with 1 GHz or faster Pentium processor

Sun UltraSPARC 60 MP with 440 MHz or faster processor

Sun UltraSPARC III (Sun Blade 2000 Workstation or Sun Fire 280R Workgroup Server)

Server hardware needs to be equipped with at least:

CD-ROM drive

100BASE-T or faster connection

1 GB RAM

9 GB available disk drive space

2 GB virtual memory

Color monitor with video card capable of 16-bit color

Server Operating System

CiscoWorks VMS requires one of the following operating systems:

Windows 2000 Professional, Server, and Advanced Server (Service Pack 4)

Note: Support for Advanced Server requires that Terminal Services be turned off.

Sun Solaris 2.8 with selected patches listed in the Quick Start Guide documentation

Java Requirements

Sun Java plug-in 1.4.1_02

Client Requirements

Hardware

CiscoWorks VMS requires one of the following for the client:

PC with 300 MHz or faster Pentium processor

Solaris SPARCstation or Sun Ultra 10

Client Operating System

CiscoWorks VMS requires one of the following for the client:

Windows 2000 Server or Professional Edition with Service Pack 4, or Windows XP Service Pack 1a

Solaris 2.8

Client Browser

All CiscoWorks VMS components support Internet Explorer 6.0 with Service Pack 1 on Windows platforms. Table 1 identifies Netscape Navigator support by individual components where these requirements differ from CiscoWorks VMS as a whole.

Table 1  Supported versions for the Netscape browser

Component
Windows Browser Requirements
Solaris Browser Requirements

CiscoWorks Common Services

CiscoWorks Resource Manager Essentials (RME)

Netscape Navigator 4.79 or

Netscape Navigator 7.1

Netscape Navigator 4.76 or

Netscape Navigator 7.0

Management Center for Firewalls

Auto Update Server

Management Center for VPN Routers

Management Center for Cisco Security Agents

VPN Monitor

Netscape Navigator 7.1

Netscape Navigator 7.0

Management Center for IDS Sensors

Monitoring Center for Security

Monitoring Center for Performance (Solaris)

Netscape Navigator 4.79

Netscape Navigator 4.76


Service and Support

CiscoWorks products are eligible for coverage under the Cisco Software Application Service (SAS) program. This service program offers customers contract-based, 24-hour access to the Cisco Technical Assistance Center (TAC), full Cisco.com privileges, and software maintenance updates. A Cisco SAS contract ensures that customers have easy access to the information and services needed to stay current with newly supported device packages, patches, and minor updates. For further information about service and support offerings, contact your local sales office.

Ordering Information

CiscoWorks VMS is available for purchase through regular Cisco sales and distribution channels worldwide. CiscoWorks VMS includes all the components needed for an independent installation on a Microsoft Windows or Sun Solaris workstation.

Positioning with CiscoWorks VMS Basic

CiscoWorks VMS Basic is bundled with select Cisco security solutions such as Cisco IDS sensors. The CiscoWorks VMS 2.2 Basic license offers the same capabilities as the CiscoWorks VMS 2.2 Restricted licensed software, except in the following areas:

The basic license does not provide the use of RME and VPN Monitor components

The basic license is limited to the management of five devices (however, the user may manage an unlimited number of Cisco security agents that are licensed and purchased separately)

For customers who need to manage 6 to 20 devices, the VMS Restricted license is recommended. For customers who need to manage more than 20 devices or need to install on Solaris, the VMS Unrestricted license is recommended.

For More Information

For more information, send an e-mail message to ciscoworks@cisco.com or go to:
http://www.cisco.com/warp/public/cc/pd/wr2k/vpmnso/prodlit/.


Toolbar

Posted: Fri Jun 18 08:31:13 PDT 2004
All contents are Copyright © 1992--2004 Cisco Systems, Inc. All rights reserved.
Important Notices and Privacy Statement.