Hi. Does someone have a solution to this:
A service provider offers firewalls to his clients. Every asa si monitored by a MARS. If the clients use the same subnets in their Local networks, how can this be solved in MARS.
I mean, in the topology dashboard the firewalls will apear as connected on their inside interfaces, and in the Incident Dashboard i will see that, let's say an atacker with 10.x.x.1 tried something, but i will not know which which client (as they both have 10.x.x.x in their local lans).
Can this be solved somehow?