<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM config in CS-MARS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715103#M1009413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where I'm getting confused is at the onset of the fwsm config.  sorry if I'm being a bit vague - the fw admins sent me the basic config info to plug into MARS so I can't speak to the entire fwsm or any particular context config.  The MARS box can currently grab syslogs from anywhere and everywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example -&lt;/P&gt;&lt;P&gt;system context hostname "fwsm1"&lt;/P&gt;&lt;P&gt;admin context "fwsmadmin", hostname adminhost"&lt;/P&gt;&lt;P&gt;security context "fwsmsec1" hostname "sechost"&lt;/P&gt;&lt;P&gt;Note that each context has a hostname associated with it which does not match the respective context name - not sure what the original logic was there - or if I even need to be concerned about the hostname parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyway, I want the admin context and the security context to report (syslog) to MARS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand I need to add the cat-os switch as a device in MARS, then add the fwsm as a module under the cat-os switch device config - so do I then have to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) use the fwsm system context info (i.e. "fwsm1", etc.) to define the module, and then add both the admin context and the security context under the fwsm module definition, or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) use the fwsm admin context info (i.e. "fwsmadmin") to define the fwsm module in MARS, and then add just define the security context as "context" under that fwsm module definition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may have gathered that I'm not a firewall guru by any stretch - just want the fwsm and all related contexts to be set up in  logical meaningful (sane) way on the MARS config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;-randy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Mar 2007 20:44:34 GMT</pubDate>
    <dc:creator>randytoni</dc:creator>
    <dc:date>2007-03-23T20:44:34Z</dc:date>
    <item>
      <title>FWSM config in CS-MARS</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715101#M1009408</link>
      <description>&lt;P&gt;I'm configuring a couple of FWSM's (2.2 and 2.3) as devices in MARS.  When I add the FWSM as a device, what do I enter as the device name and reporting / access IPs?  Should the device name and / or IP info be the same as the FWSM's admin context? or should I be worried about using the name of the system context, etc.?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I gather once this is done (FWSM is defined as a device), the only "contexts" I need to define are the security contexts (i.e. I don't need to explicilty define an admin context within the list of defined contexts for the FWSM...?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;am I making sense?  the docs are just too ambiguous&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;-randy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715101#M1009408</guid>
      <dc:creator>randytoni</dc:creator>
      <dc:date>2019-03-11T09:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM config in CS-MARS</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715102#M1009410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would depend on what you want to see in MARS, and want you want MARS to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sending syslog messages from the contexts is easy enough...set logging parameters in each context, and 1-2-3 go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your questions...how are the contexts configured, regarding IP addresses? Are there transit VLAN's? Where does MARS reside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 19:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715102#M1009410</guid>
      <dc:creator>astroman</dc:creator>
      <dc:date>2007-03-23T19:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM config in CS-MARS</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715103#M1009413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where I'm getting confused is at the onset of the fwsm config.  sorry if I'm being a bit vague - the fw admins sent me the basic config info to plug into MARS so I can't speak to the entire fwsm or any particular context config.  The MARS box can currently grab syslogs from anywhere and everywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example -&lt;/P&gt;&lt;P&gt;system context hostname "fwsm1"&lt;/P&gt;&lt;P&gt;admin context "fwsmadmin", hostname adminhost"&lt;/P&gt;&lt;P&gt;security context "fwsmsec1" hostname "sechost"&lt;/P&gt;&lt;P&gt;Note that each context has a hostname associated with it which does not match the respective context name - not sure what the original logic was there - or if I even need to be concerned about the hostname parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyway, I want the admin context and the security context to report (syslog) to MARS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand I need to add the cat-os switch as a device in MARS, then add the fwsm as a module under the cat-os switch device config - so do I then have to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) use the fwsm system context info (i.e. "fwsm1", etc.) to define the module, and then add both the admin context and the security context under the fwsm module definition, or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) use the fwsm admin context info (i.e. "fwsmadmin") to define the fwsm module in MARS, and then add just define the security context as "context" under that fwsm module definition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may have gathered that I'm not a firewall guru by any stretch - just want the fwsm and all related contexts to be set up in  logical meaningful (sane) way on the MARS config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;-randy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 20:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-config-in-cs-mars/m-p/715103#M1009413</guid>
      <dc:creator>randytoni</dc:creator>
      <dc:date>2007-03-23T20:44:34Z</dc:date>
    </item>
  </channel>
</rss>

