CS-MARS unable to compute mitigation path for external IPs

Unanswered Question
Sep 26th, 2007
User Badges:


I have a MARS and IDSM setup running and has been monitoring two internal VLANS with the IDSM. I get some notices in the IDSM and MARS for attempts flowing through our open firewall rules, nothing serious and I can get a path and mitigation suggestion for every attempt.

A few days ago I added our external unprotected VLAN to the IDSM and not surprisingly get alot more incidents in the IDSM and MARS. The problem is that none of these events can be graphed in MARS, it doesn't matter what type of events I get or if the events are aimed at valid NATed IPs or available IPs.

The only addition I've done to the MARS after adding the external VLAN to the IDSM is to add our external subnet to the list of networks monitored by the IDSM.

Do I have to change something else? My impression was that MARS should download NATsetups from our firewalls and use that to plot the network paths.


Fredrik Hofgren

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
michaelwoolfe Fri, 09/28/2007 - 06:48
User Badges:

I believe that MARS does a topology discovery through the "Topology/Monitored Device Update Scheduler". We use to run a MARS based topology scanner before we started using Qualys. See what results you can get from a manual run??

Also, what version and model of MARS are you currently running?

hoffa2000 Sat, 09/29/2007 - 04:11
User Badges:

I'm running 4.3.1 and have run several over night topology updates without effect. What I've done now is to remove the IDSM monitoring on our external VLAN and MARS can now graph the route of the packets again.

I'll leave it as it is for a while but if anyone have a solution I'd appreciate it



jfgobin01 Sun, 09/30/2007 - 22:54
User Badges:


In the IDSM configuration (is this also functionning with contexts ?), did you precise which networks are protected ? With the NAT addresses or real addresses ?


hoffa2000 Mon, 10/01/2007 - 01:42
User Badges:

I'm not running the IDSM in context mode. In MARS I specified our two internal subnets and our external subnet as monitored by the IDSM.

I can add that I just tried to monitor the external VLAN but not specify it in MARS but I still get the same problem when graphing external events.



This Discussion