Is it recommended to have the Concentrator behind a firewall, or can it just be placed in parallel (like the documentation suggests).If behind say a PIX, what ports do i need open for this to work.Ta.
Hi PaulIf you run a query, on RAW Event, from just the Concentrator (over the last hour or so, or real-time) do you see any events coming in?Chrisciscomars.blogspot.com
Hi PaulYou dont mention what authentication method you are using or type of vpn session (IPSEC or SSL)I`ve not had chance to test this, but looking at the Events for the Concentrator...VPN ConcentratorConfiguration>System>Events>GeneralSelect the Eve...
Its a good read, but you will not find too much that is not in the manual already.Some good info on the database etc, and some casestudies.You`ll also find some other info on a couple of blogs i`ve seen cs-mars.blogspot.com and ciscomars.blogspot.com
Hi, what do you want to know? Checkpoint will basically send all its event logs over to the MARS box. You will see incidents created, for Rules that Fire, like config changes, SmartDefence Blocks, Worms, Peer to Peer etc