Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ISDM Mgmt & Monitoring

We bought 2 IDSMs, and currently are in the stage of evaluating different Management & Monitoring software, like MARS,Enterasys, etc, and would appreciate your hands-on experience and comments. thanks.

1 REPLY
New Member

Re: ISDM Mgmt & Monitoring

Hi

I have two IDSMs online in our two 6513 and one MARS 50 to gather the information. I use the web interface, IDM, supplied with the IDSMs to manage the devices but only use MARS to monitor the dataflow, so far I haven't tuned any signatures on the IDSMs, I let MARS drop the false positives as suggested by the MARS manual.

I have worked alot with Snort and ACID before, although it cannot compare to the IDSM/MARS setup it is the only previous experience I have in security monitoring. I would say the MARS is a great tool for monitoring company wide security events and it helps you declutter the IDS traffic but it doesn't really "manage" the IDSMs as such, for that you might need another tool.

Regards

Fredrik

118
Views
4
Helpful
1
Replies