<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall, IPS and MARS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430845#M667900</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does help. I am new to the organization that I work for and security equipment is not my strong area, so I have alot to learn. These 3 pieces have already been configured here by someone else. I'm not sure if they are all configured correctly or not, and that person is no longer here. I see the benefit of the ASA and the IPS, however the MARS is a little more unfriendly in terms of deciphering the events.&lt;/P&gt;&lt;P&gt;When I first started looking at the different products, it seemed like the ASA and IPS were doing similar things, and I thought that the ASA 5510 had an IPS built into it?&lt;/P&gt;&lt;P&gt;My manager was just curious if all three products were needed.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Jul 2010 13:33:10 GMT</pubDate>
    <dc:creator>mhomp</dc:creator>
    <dc:date>2010-07-13T13:33:10Z</dc:date>
    <item>
      <title>Firewall, IPS and MARS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430843#M667888</link>
      <description>&lt;P&gt;I work at a small to medium sized business, where we have a Firewall (Cisco ASA 5510), an IPS System (Cisco IDM), and A Cisco MARS device. Is it neccessary to have all 3?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430843#M667888</guid>
      <dc:creator>mhomp</dc:creator>
      <dc:date>2019-03-11T18:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall, IPS and MARS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430844#M667897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marsha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These three devices actually serve totally different functions.&amp;nbsp; The firewall is meant to block traffic due to access-lists (implicit or explicit) while also providing NAT and other policy enforcement.&amp;nbsp; With the ASA, this firewall will also open any secondary ports for relevant protocols (ie H323, FTP, SIP, SCCP, etc).&amp;nbsp; The IPS is optimized to characterize the traffic contents in attempts to detect malicious attacks.&amp;nbsp; For instance, the IPS is optimized to detect some virii, trojan horses, and other malicious traffic patterns based on packet-level inspection.&amp;nbsp; The MARS device helps to correlate the various security events across the network to glean whether or not an attack is in progress.&amp;nbsp; This can be most effective if a single host/subnet is causing security events on different devices at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All three of these tools, when used correctly, can contribute equally to the security of your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this answers your question!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 13:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430844#M667897</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-07-13T13:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall, IPS and MARS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430845#M667900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does help. I am new to the organization that I work for and security equipment is not my strong area, so I have alot to learn. These 3 pieces have already been configured here by someone else. I'm not sure if they are all configured correctly or not, and that person is no longer here. I see the benefit of the ASA and the IPS, however the MARS is a little more unfriendly in terms of deciphering the events.&lt;/P&gt;&lt;P&gt;When I first started looking at the different products, it seemed like the ASA and IPS were doing similar things, and I thought that the ASA 5510 had an IPS built into it?&lt;/P&gt;&lt;P&gt;My manager was just curious if all three products were needed.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 13:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430845#M667900</guid>
      <dc:creator>mhomp</dc:creator>
      <dc:date>2010-07-13T13:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall, IPS and MARS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430846#M667909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA will do your basic firewalling.&lt;/P&gt;&lt;P&gt;The IPS will be checking for attacks, virus patterns and other signatures.&lt;/P&gt;&lt;P&gt;MARS is a tool that collects syslogs from all devices and puts them together and can give you reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you ask me the first two are more essential than then 3rd, even though the 3rd can be very useful at times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 13:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430846#M667909</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-07-13T13:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall, IPS and MARS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430847#M667922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marsha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA 5510 and ASA 5520 can have an IPS module built into it.&amp;nbsp; Depending on your network topology and Security policy, you may choose to have both an IPS and/or IDS at different points in your network - giving you one more opportunity to mitigate any attacks whether they are internal to your network or external.&amp;nbsp; Also, if you are needing to process more data than is supported by the AIP (the IPS module that is available for the ASA), a standalone device may prove useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need additional assistance in configuring MARS device and understanding event correlation, please feel free to open a Service Request with our Network Management TAC team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 14:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ips-and-mars/m-p/1430847#M667922</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-07-13T14:02:51Z</dc:date>
    </item>
  </channel>
</rss>

